Server-Side Request Forgery in OutSystems Platform Server
CVE-2021-29357

8.6HIGH

What is CVE-2021-29357?

The ECT Provider component in OutSystems Platform Server versions before 10.0.1104.0 and 11.9.0, along with the LifeTime management console prior to version 11.7.0, is susceptible to Server-Side Request Forgery (SSRF). This vulnerability allows an attacker to make arbitrary HTTP requests from the server, potentially exposing sensitive internal services or information. Proper mitigation is essential to prevent unauthorized access and safeguard sensitive data.

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.