SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-7553

The external_request api call in App Studio (millicore) allows server side request forgery (SSRF).

MEDIUM 6.3EPSS 0.70%

Does this matter?

Lower severity and a low EPSS score (0.70%). Track it; it rarely justifies an emergency change on its own.

Description

The external_request api call in App Studio (millicore) allows server side request forgery (SSRF). An attacker could use this flaw to probe the network internal resources, and access restricted endpoints.

CVSS 3.0
6.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS
0.70% probability · 51th percentile
CISA KEV
Not listed
Weakness
CWE-918
Affected
redhat/mobile application platform
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.