Server-Side Request Forgery (SSRF) in Amazon EC2 - CVE-2020-2091

 

Server-Side Request Forgery (SSRF) in Amazon EC2 - CVE-2020-2091

Published: January 16, 2020


Vulnerability identifier: #VU24345
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2020-2091
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform SSRF attacks.

The vulnerability exists due to the affected software does not perform permission checks in methods performing form validation. A remote user with Overall/Read access can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.

Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.


Affected software

Amazon EC2

How to mitigate CVE-2020-2091

Install updates from vendor's website.

Amazon EC2 - update to 1.48

External References

Related Security Bulletins