Vulnerability Description
Concrete CMS (formerly concrete5) versions below 8.5.7 has a SSRF mitigation bypass using DNS Rebind attack giving an attacker the ability to fetch cloud IAAS (ex AWS) IAM keys.To fix this Concrete CMS no longer allows downloads from the local network and specifies the validated IP when downloading rather than relying on DNS.Discoverer: Adrian Tiron from FORTBRIDGE ( https://www.fortbridge.co.uk/ )The Concrete CMS team gave this a CVSS 3.1 score of 3.5 AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N . Please note that Cloud IAAS provider mis-configurations are not Concrete CMS vulnerabilities. A mitigation for this vulnerability is to make sure that the IMDS configurations are according to a cloud provider's best practices.This fix is also in Concrete version 9.0.0
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Concretecms | Concrete Cms | < 8.5.7 |
Related Weaknesses (CWE)
References
- https://documentation.concretecms.org/developers/introduction/version-history/85Release NotesVendor Advisory
- https://hackerone.com/reports/1369312Permissions Required
- https://documentation.concretecms.org/developers/introduction/version-history/85Release NotesVendor Advisory
- https://hackerone.com/reports/1369312Permissions Required
FAQ
What is CVE-2021-22969?
CVE-2021-22969 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Concrete CMS (formerly concrete5) versions below 8.5.7 has a SSRF mitigation bypass using DNS Rebind attack giving an attacker the ability to fetch cloud IAAS (ex AWS) IAM keys.To fix this Concrete CM...
How severe is CVE-2021-22969?
CVE-2021-22969 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-22969?
Check the references section above for vendor advisories and patch information. Affected products include: Concretecms Concrete Cms.