SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-41792

The response to the request is not available to the attacker, i.e., this is blind SSRF.

MEDIUM 5.3EPSS 0.86%

Does this matter?

Lower severity and a low EPSS score (0.86%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in Hyland org.alfresco:alfresco-content-services through 6.2.2.18 and org.alfresco:alfresco-transform-services through 1.3. A crafted HTML file, once uploaded, could trigger an unexpected request by the transformation engine. The response to the request is not available to the attacker, i.e., this is blind SSRF.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
0.86% probability · 56th percentile
CISA KEV
Not listed
Weakness
CWE-918
Affected
alfresco/alfresco content services · alfresco/alfresco transform services
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.