CVE-2018-12678

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
22/06/2018
Last modified:
13/08/2018

Description

Portainer before 1.18.0 supports unauthenticated requests to the websocket endpoint with an unvalidated id query parameter for the /websocket/exec endpoint, which allows remote attackers to bypass intended access restrictions or conduct SSRF attacks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:portainer:portainer:*:*:*:*:*:*:*:* 1.18.0 (excluding)