CVE-2017-7553

Impact:
Moderate
Public Date:
2017-09-11
CWE:
CWE-918
Bugzilla:
1478792: CVE-2017-7553 RHMAP: SSRF via external_request feature of App Studio
The external_request api call in App Studio (millicore) allows server side request forgery (SSRF). An attacker could use this flaw to probe the network internal resources and access restricted endpoints.

Find out more about CVE-2017-7553 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

CVSS3 Base Score 6
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L
Attack Vector Network
Attack Complexity High
Privileges Required Low
User Interaction None
Scope Changed
Confidentiality Low
Integrity Impact Low
Availability Impact Low

Red Hat Security Errata

Platform Errata Release Date
Red Hat Mobile Application Platform 4.5 RHSA-2017:2674 2017-09-18
Red Hat Mobile Application Platform 4.5 RHSA-2017:2675 2017-09-18

Affected Packages State

Platform Package State
Red Hat Mobile Application Platform On-Premise 4 millicore Will not fix

Acknowledgements

Red Hat would like to thank Tomas Rzepka for reporting this issue.

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.