CVE-2022-23206

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
06/02/2022
Last modified:
11/02/2022

Description

In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS can send a specially-crafted POST request to /user/login/oauth to scan a port of a server that Traffic Ops can reach.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:traffic_control:*:*:*:*:*:*:*:* 5.1.6 (excluding)
cpe:2.3:a:apache:traffic_control:*:*:*:*:*:*:*:* 6.0.0 (including) 6.1.0 (excluding)


References to Advisories, Solutions, and Tools