CVE-2017-7553
published 2017-09-29CVE-2017-7553: The external_request api call in App Studio (millicore) allows server side request forgery (SSRF). An attacker could use this flaw to probe the network…
PriorityP335medium6.3CVSS 3.0
AVNACLPRLUINSUCLILAL
EPSS
0.70%
49.1th percentile
The external_request api call in App Studio (millicore) allows server side request forgery (SSRF). An attacker could use this flaw to probe the network internal resources, and access restricted endpoints.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| irssi | irssi | >= 0 < 0.8.15-5ubuntu3.1 | 0.8.15-5ubuntu3.1 |
| irssi | irssi | >= 0 < 0.8.19-1ubuntu1.3 | 0.8.19-1ubuntu1.3 |
| redhat | mobile_application_platform | <= 4.4.3 | — |
CVSS provenance
nvdv3.06.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv3.3LOW
vendor_redhat6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
RHMAP: SSRF via external_request feature of App Studio
vendor_redhat·2017-09-11·CVSS 6.3
CVE-2017-7553 [MEDIUM] CWE-918 RHMAP: SSRF via external_request feature of App Studio
RHMAP: SSRF via external_request feature of App Studio
The external_request api call in App Studio (millicore) allows server side request forgery (SSRF). An attacker could use this flaw to probe the network internal resources, and access restricted endpoints.
The external_request api call in App Studio (millicore) allows server side request forgery (SSRF). An attacker could use this flaw to probe the network internal resources and access restricted endpoints.
GHSA
GHSA-rmmq-9vg2-553m: The external_request api call in App Studio (millicore) allows server side request forgery (SSRF)
ghsa_unreviewed·2022-05-14
CVE-2017-7553 [MEDIUM] CWE-918 GHSA-rmmq-9vg2-553m: The external_request api call in App Studio (millicore) allows server side request forgery (SSRF)
The external_request api call in App Studio (millicore) allows server side request forgery (SSRF). An attacker could use this flaw to probe the network internal resources, and access restricted endpoints.
OSV
irssi vulnerabilities
osv·2017-02-01·CVSS 3.3
CVE-2016-7553 irssi vulnerabilities
irssi vulnerabilities
It was discovered that the Irssi buf.pl script set incorrect permissions. A
local attacker could use this issue to retrieve another user's window
contents. (CVE-2016-7553)
Joseph Bisch discovered that Irssi incorrectly handled comparing nicks. A
remote attacker could use this issue to cause Irssi to crash, resulting in
a denial of service, or possibly execute arbitrary code. (CVE-2017-5193)
It was discovered that Irssi incorrectly handled invalid nick messages. A
remote attacker could use this issue to cause Irssi to crash, resulting in
a denial of service, or possibly execute arbitrary code. (CVE-2017-5194)
Joseph Bisch discovered that Irssi incorrectly handled certain incomplete
control codes. A remote attacker could use this issue to cause Irssi to
crash, resul
No detection rules found.
No public exploits indexed.
2017-09-29
Published