CVE-2021-31216
Last modified
CVE-2021-31216 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. Siren Investigate before 11.1.1 contains a server side request forgery (SSRF) defect in the built-in image proxy route (which is enabled by default). An attacker with access to the Investigate installation can specify an arbitrary URL in the parameters of the image proxy route and fetch external URLs as the Investigate process on the host.. EPSS estimates a 0.72% chance of exploitation in the next 30 days.
Description
Siren Investigate before 11.1.1 contains a server side request forgery (SSRF) defect in the built-in image proxy route (which is enabled by default). An attacker with access to the Investigate installation can specify an arbitrary URL in the parameters of the image proxy route and fetch external URLs as the Investigate process on the host.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Siren | Investigate | < 11.1.1 |
References
- https://community.siren.io/c/announcementsRelease Notes, Vendor Advisory
- https://docs.siren.io/siren-platform-user-guide/11.1/release-notes.htmlPatch, Release Notes, Vendor Advisory
- https://community.siren.io/c/announcementsRelease Notes, Vendor Advisory
- https://docs.siren.io/siren-platform-user-guide/11.1/release-notes.htmlPatch, Release Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-31216?
How severe is CVE-2021-31216?
How do I fix CVE-2021-31216?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-31209Microsoft Exchange Server Spoofing Vulnerability6.5
- CVE-2021-3121An issue was discovered in GoGo Protobuf before 1.3.2. plugi…8.6
- CVE-2021-31211Visual Studio Code Remote Code Execution Vulnerability7.8
- CVE-2021-31213Visual Studio Code Remote Containers Extension Remote Code E…7.8
- CVE-2021-31214Visual Studio Code Remote Code Execution Vulnerability7.8
- CVE-2021-31215SchedMD Slurm before 20.02.7 and 20.03.x through 20.11.x bef…8.8
- CVE-2021-31217In SolarWinds DameWare Mini Remote Control Server 12.0.1.200…9.1
- CVE-2021-3122CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH s…9.8
- CVE-2021-31220SES Evolution before 2.1.0 allows modifying security policie…5.2
- CVE-2021-31221SES Evolution before 2.1.0 allows deleting some parts of a s…5.7
- CVE-2021-31222SES Evolution before 2.1.0 allows updating some parts of a s…5.7
- CVE-2021-31223SES Evolution before 2.1.0 allows reading some parts of a se…5.7
Are you affected by CVE-2021-31216?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
