CVE-2023-45705Server-Side Request Forgery in Bigfix Platform

Severity
7.2HIGHNVD
CNA3.5
EPSS
0.2%
top 53.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 28

Description

An administrative user of WebReports may perform a Server Side Request Forgery (SSRF) exploit through SMTP configuration options.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages2 packages

NVDhcltech/bigfix_platform1010.0.11+1
CVEListV5hcl_software/bigfix_platform10.0 - 10.0.10, 11.0.0 - 11.0.1

🔴Vulnerability Details

2
CVEList
HCL BigFix Platform is susceptible to Server Side Request Forgery (SSRF)2024-03-28
GHSA
GHSA-3x3h-fcc9-p4px: An administrative user of WebReports may perform a Server Side Request Forgery (SSRF) exploit through SMTP configuration options2024-03-28
CVE-2023-45705 — Server-Side Request Forgery | cvebase