CVE-2023-24515

Server-Side Request Forgery (SSRF) vulnerability in API checker of Pandora FMS. Application does not have a check on the URL scheme used while retrieving API URL. Rather than validating the http/https scheme, the application allows other scheme such as file, which could allow a malicious user to fetch internal file content. This issue affects Pandora FMS v767 version and prior versions on all platforms.
Configurations

Configuration 1 (hide)

cpe:2.3:a:pandorafms:pandora_fms:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:48

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 5.2
References () https://gist.github.com/damodarnaik/9cc76c6b320510c34a0a668bd7439f7b - () https://gist.github.com/damodarnaik/9cc76c6b320510c34a0a668bd7439f7b -
References () https://pandorafms.com/en/security/common-vulnerabilities-and-exposures/ - Vendor Advisory () https://pandorafms.com/en/security/common-vulnerabilities-and-exposures/ - Vendor Advisory
Summary
  • (es) Vulnerabilidad de falsificación de petición del lado del servidor (SSRF) en el comprobador de API de Pandora FMS. La aplicación no comprueba el esquema de URL utilizado al recuperar la URL de la API. En lugar de validar el esquema http/https, la aplicación permite otros esquemas como file, lo que podría permitir a un usuario malicioso obtener contenido de ficheros internos. Este problema afecta a Pandora FMS v767 y versiones anteriores en todas las plataformas.

Information

Published : 2023-08-22 19:16

Updated : 2024-11-21 07:48


NVD link : CVE-2023-24515

Mitre link : CVE-2023-24515

CVE.ORG link : CVE-2023-24515


JSON object : View

Products Affected

pandorafms

  • pandora_fms
CWE
CWE-918

Server-Side Request Forgery (SSRF)