CVE-2023-44313
Last modified
CVE-2023-44313 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Server-Side Request Forgery (SSRF) vulnerability in Apache ServiceComb Service-Center. Attackers can obtain sensitive server information through specially crafted requests.This issue affects Apache ServiceComb before 2.1.0(include). Users are recommended to upgrade to version 2.2.0, which fixes the issue.. EPSS estimates a 3.46% chance of exploitation in the next 30 days.
Description
Server-Side Request Forgery (SSRF) vulnerability in Apache ServiceComb Service-Center. Attackers can obtain sensitive server information through specially crafted requests.This issue affects Apache ServiceComb before 2.1.0(include). Users are recommended to upgrade to version 2.2.0, which fixes the issue.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Servicecomb | < 2.2.0 |
References
- https://www.openwall.com/lists/oss-security/2024/01/31/4Mailing List, Third Party Advisory
- https://lists.apache.org/thread/kxovd455o9h4f2v811hcov2qknbwld5rMailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2024/01/31/4Mailing List, Third Party Advisory
- https://lists.apache.org/thread/kxovd455o9h4f2v811hcov2qknbwld5rMailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-44313?
How severe is CVE-2023-44313?
How do I fix CVE-2023-44313?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-44308Open redirect vulnerability in adaptive media administration…6.1
- CVE-2023-44309Multiple stored cross-site scripting (XSS) vulnerabilities i…5.4
- CVE-2023-4431Out of bounds memory access in Fonts in Google Chrome prior …8.1
- CVE-2023-44310Stored cross-site scripting (XSS) vulnerability in Page Tree…5.4
- CVE-2023-44311Multiple reflected cross-site scripting (XSS) vulnerabilitie…6.1
- CVE-2023-44312Exposure of Sensitive Information to an Unauthorized Actor i…7.5
- CVE-2023-44315A vulnerability has been identified in SINEC NMS (All versio…5.4
- CVE-2023-44317A vulnerability has been identified in RUGGEDCOM RM1224 LTE(…8.6
- CVE-2023-44318Affected devices use a hardcoded key to obfuscate the config…4.9
- CVE-2023-44319A vulnerability has been identified in RUGGEDCOM RM1224 LTE(…4.9
- CVE-2023-4432Cross-site Scripting (XSS) - Reflected in GitHub repository …6.1
- CVE-2023-44320A vulnerability has been identified in RUGGEDCOM RM1224 LTE(…4.3
Are you affected by CVE-2023-44313?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
