CVE-2021-22969
Last modified
CVE-2021-22969 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Concrete CMS (formerly concrete5) versions below 8.5.7 has a SSRF mitigation bypass using DNS Rebind attack giving an attacker the ability to fetch cloud IAAS (ex AWS) IAM keys.To fix this Concrete CMS no longer allows downloads from the local network and specifies the validated IP when downloading rather than relying on DNS.Discoverer: Adrian Tiron from FORTBRIDGE ( https://www.fortbridge.co.uk/ )The Concrete CMS team gave this a CVSS 3.1 score of 3.5 AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N . Please note that Cloud IAAS provider mis-configurations are not Concrete CMS vulnerabilities. EPSS estimates a 0.83% chance of exploitation in the next 30 days.
Description
Concrete CMS (formerly concrete5) versions below 8.5.7 has a SSRF mitigation bypass using DNS Rebind attack giving an attacker the ability to fetch cloud IAAS (ex AWS) IAM keys.To fix this Concrete CMS no longer allows downloads from the local network and specifies the validated IP when downloading rather than relying on DNS.Discoverer: Adrian Tiron from FORTBRIDGE ( https://www.fortbridge.co.uk/ )The Concrete CMS team gave this a CVSS 3.1 score of 3.5 AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N . Please note that Cloud IAAS provider mis-configurations are not Concrete CMS vulnerabilities. A mitigation for this vulnerability is to make sure that the IMDS configurations are according to a cloud provider's best practices.This fix is also in Concrete version 9.0.0
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Concretecms | Concrete Cms | < 8.5.7 |
References
- https://documentation.concretecms.org/developers/introduction/version-history/857-release-notesRelease Notes, Vendor Advisory
- https://hackerone.com/reports/1369312Permissions Required
- https://documentation.concretecms.org/developers/introduction/version-history/857-release-notesRelease Notes, Vendor Advisory
- https://hackerone.com/reports/1369312Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-22969?
How severe is CVE-2021-22969?
How do I fix CVE-2021-22969?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-22963A redirect vulnerability in the fastify-static module versio…6.1
- CVE-2021-22964A redirect vulnerability in the `fastify-static` module vers…8.8
- CVE-2021-22965A vulnerability in Pulse Connect Secure before 9.1R12.1 coul…7.5
- CVE-2021-22966Privilege escalation from Editor to Admin using Groups in Co…8.8
- CVE-2021-22967In Concrete CMS (formerly concrete 5) below 8.5.7, IDOR Allo…7.5
- CVE-2021-22968A bypass of adding remote files in Concrete CMS (previously …7.2
- CVE-2021-2297Vulnerability in the Oracle VM VirtualBox product of Oracle …5.3
- CVE-2021-22970Concrete CMS (formerly concrete5) versions 8.5.6 and below a…7.5
- CVE-2021-22973On BIG-IP version 16.0.x before 16.0.1.1, 15.1.x before 15.1…7.5
- CVE-2021-22974On BIG-IP version 16.0.x before 16.0.1.1, 15.1.x before 15.1…7.5
- CVE-2021-22975On BIG-IP version 16.0.x before 16.0.1.1, 15.1.x before 15.1…7.5
- CVE-2021-22976On BIG-IP Advanced WAF and ASM version 16.0.x before 16.0.1.…7.5
Are you affected by CVE-2021-22969?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
