Description
Engelsystem is a shift planning system for chaos events. A Blind SSRF in the "Import schedule" functionality makes it possible to perform a port scan against the local environment. This vulnerability has been fixed in commit ee7d30b33. If a patch cannot be deployed, operators should ensure that no HTTP(s) services listen on localhost and/or systems only reachable from the host running the engelsystem software. If such services are necessary, they should utilize additional authentication.
Published: 2023-10-16
Score: 2 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-49459 Engelsystem is a shift planning system for chaos events. A Blind SSRF in the "Import schedule" functionality makes it possible to perform a port scan against the local environment. This vulnerability has been fixed in commit ee7d30b33. If a patch cannot be deployed, operators should ensure that no HTTP(s) services listen on localhost and/or systems only reachable from the host running the engelsystem software. If such services are necessary, they should utilize additional authentication.
History

No history.

Subscriptions

Engelsystem Engelsystem
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-09-13T20:11:31.632Z

Reserved: 2023-10-04T16:02:46.331Z

Link: CVE-2023-45152

cve-icon Vulnrichment

Updated: 2024-08-02T20:14:19.046Z

cve-icon NVD

Status : Modified

Published: 2023-10-17T00:15:11.140

Modified: 2024-11-21T08:26:27.290

Link: CVE-2023-45152

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses