go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Changing Information Technology Inc. RAVA certificate validation system - Server-Side Request Forgery (SSRF)

TVN ID TVN-202209011
CVE ID CVE-2022-39055
CVSS 5.3 (Medium)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Products Changing Information Technology Inc. RAVA certificate validation system v3
Description RAVA certificate validation system has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform SSRF attack to discover internal network topology base on query response.
Solution Contact tech support from Changing
Credit Jay Wu吳瑋杰 (Acer Cyber Security Inc., ACSI)
Public Date 2022-10-18
Top