High7.2
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N

PT-2024-34: Server Side Request Forgery (SSRF) in Passwork

PT-2024-34: Server Side Request Forgery (SSRF) in Passwork

Vendor: Passwork

Vulnerable product: Passwork

Vulnerable version: 6.4.0

Vulnerability type:

CWE-918: Server-Side Request Forgery (SSRF)

Identifier (ID):

BDU:2024-08019

Vulnerability vector:

Base vulnerability score (CVSSv3.1): CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Severity (CVSSv3.1): 8.1(high)

Base vulnerability score (CVSSv4.0): CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N

Severity (CVSSv4.0): 7.2(high)

Description:

The vulnerability was identified in Passwork version 6.4.0.

The discovered vulnerability can be exploited by an attacker to send requests to both external nodes and servers with limited access, which leads to disclosure of sentisive data, denial of service, etc.

Also, exploitation of the vulnerability allows an attacker to conduct attacks on external servers in order to hide the attacker's own address; obtain information about the structure of internal network segments that are inaccessible to the attacker; access internal resources, scan ports/services, etc.

Vulnerability status: Confirmed by vendor

Date of vulnerability remediation: 09.10.2024

Recommendations:

Update to version 6.4.3 or higher

Additional information: Aleksey Pisarenko (Positive Technologies)