Server-Side Request Forgery (SSRF) in axios - CVE-2020-28168
Published: November 6, 2020 / Updated: January 4, 2021
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address and trick the application to initiate requests to arbitrary systems.
Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.
Affected software
BigBlueButton
IBM Integration Bus
IBM Sterling Control Center
SINEC INS
IBM Planning Analytics Workspace
IBM Cloud Pak System
IBM App Connect Enterprise
How to mitigate CVE-2020-28168
BigBlueButton - update to 2.2.32
SINEC INS - update to 1.0 SP2
IBM Planning Analytics Workspace - update to 2.0.93
IBM Cloud Pak System - update to 2.3.3.7 iFix 01
IBM App Connect Enterprise - update to 11.0.0.11
External References
Related Security Bulletins
- SSRF in Axios NPM package
- BigBlueButton update for axios
- SSRF in IBM Sterling Control Center
- Multiple vulnerabilities in Siemens SINEC INS
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in IBM Planning Analytics Workspace
- Multiple vulnerabilities in IBM App Connect Enterprise and IBM Integration Bus