Server-Side Request Forgery in Bitdefender GravityZone Update Server in Relay Mode (VA-10145)
CVE-2021-3959
6.8MEDIUM
What is CVE-2021-3959?
A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security Tools allows an attacker to proxy requests to the relay server. This issue affects: Bitdefender Bitdefender GravityZone versions prior to 3.3.8.272
Affected Version(s)
GravityZone < 3.3.8.272