cbcvebase.
CVE-2024-53696
published 2025-03-07

CVE-2024-53696: A server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers who…

medium5.1CVSS 4.0
AVNACLATNPRHUINVCLVINVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
A server-side request forgery (SSRF) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers who have gained administrator access to read application data. We have already fixed the vulnerability in the following versions: QuLog Center 1.7.0.829 ( 2024/10/01 ) and later QuLog Center 1.8.0.888 ( 2024/10/15 ) and later QTS 4.5.4.2957 build 20241119 and later QuTS hero h4.5.4.2956 build 20241119 and later

Affected

8 ranges
VendorProductVersion rangeFixed in
qnapqts>= 4.5.1 < 4.5.4.29574.5.4.2957
qnapqulog_center>= 1.7.0 < 1.7.0.8291.7.0.829
qnapqulog_center>= 1.8.0 < 1.8.0.8881.8.0.888
qnapquts_hero>= h4.5.0 < h4.5.4.2476h4.5.4.2476
qnap_systems_incqts>= 4.5.x < 4.5.4.2957 build 202411194.5.4.2957 build 20241119
qnap_systems_incqulog_center>= 1.7.x.x < 1.7.0.829 ( 2024/10/01 )1.7.0.829 ( 2024/10/01 )
qnap_systems_incqulog_center>= 1.8.x.x < 1.8.0.888 ( 2024/10/15 )1.8.0.888 ( 2024/10/15 )
qnap_systems_incquts_hero>= h4.5.x < h4.5.4.2956 build 20241119h4.5.4.2956 build 20241119