[Forgot Password]
Login  Register Subscribe

23631

 
 

127000

 
 

102010

 
 

909

 
 

81309

 
 

123

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML view JSON

CVE-2017-6201Date: (C)2018-02-07   (M)2018-02-19


A Server Side Request Forgery vulnerability exists in the install app process in Sandstorm before build 0.203. A remote attacker may exploit this issue by providing a URL. It could bypass access control such as firewalls that prevent the attackers from accessing the URLs directly.

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score  : CVSS Score  :
Exploit Score: Exploit Score:
Impact Score : Impact Score :
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: Access Vector:
Attack Complexity: Access Complexity:
Privileges Required: Authentication:
User Interaction: Confidentiality:
Scope: Integrity:
Confidentiality: Availability:
Integrity:  
Availability:  
  





Reference:
https://devco.re/blog/2018/01/26/Sandstorm-Security-Review-CVE-2017-6200-en/
https://github.com/sandstorm-io/sandstorm/commit/164997fb958effbc90c5328c166706280a84aaa1
https://sandstorm.io/news/2017-03-02-security-review

© 2013 SecPod Technologies