app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated users to trigger outbound TCP requests (aka SSRF) via the Test Connection feature (aka testGrafanaConnection) of the Grafana Module.
References
Configurations
History
No history.
Information
Published : 2020-03-25 14:15
Updated : 2020-03-27 17:16
NVD link : CVE-2020-10791
Mitre link : CVE-2020-10791
CVE.ORG link : CVE-2020-10791
JSON object : View
Products Affected
it-novum
- openitcockpit
CWE
CWE-918
Server-Side Request Forgery (SSRF)