Vulnerability Description
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10, a server-side-request-forgery (SSRF) vulnerability allowed an unauthenticated user to trigger a GET request as the server to an arbitrary endpoint and URL scheme. This also allows remote access to files visible to the Apache user group. Other impacts vary based on server configuration. Version 1.5.10 contains a patch.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fogproject | Fogproject | < 1.5.10 |
Related Weaknesses (CWE)
References
- https://github.com/FOGProject/fogproject/commit/9125f35ff649a3e7fd7771b1c8e5add3Patch
- https://github.com/FOGProject/fogproject/security/advisories/GHSA-8qg4-9363-873hVendor Advisory
- https://github.com/FOGProject/fogproject/commit/9125f35ff649a3e7fd7771b1c8e5add3Patch
- https://github.com/FOGProject/fogproject/security/advisories/GHSA-8qg4-9363-873hVendor Advisory
FAQ
What is CVE-2023-46236?
CVE-2023-46236 is a vulnerability with a CVSS score of 8.6 (HIGH). FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10, a server-side-request-forgery (SSRF) vulnerability allowed an unauthenticated user to trigg...
How severe is CVE-2023-46236?
CVE-2023-46236 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-46236?
Check the references section above for vendor advisories and patch information. Affected products include: Fogproject Fogproject.