Server-Side Request Forgery in Logpoint SOAR
CVE-2024-48951

Currently unrated

Key Information:

Vendor

Logpoint

Status
Vendor
CVE Published:
7 November 2024

What is CVE-2024-48951?

A vulnerability exists in Logpoint's SOAR platform that allows an attacker to exploit a Server-Side Request Forgery (SSRF) flaw. This security issue enables unauthorized access to the internal infrastructure, leading to the potential leakage of Logpoint’s API tokens. If successfully exploited, this could allow an attacker to bypass authentication mechanisms, leading to possible data breaches and system compromise. Organizations using affected versions of Logpoint SOAR are encouraged to assess the impact of this vulnerability and apply available patches to mitigate the risks.

References

Timeline

  • Vulnerability published

.