SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-49094

An attacker could make Symbolicator send arbitrary GET HTTP requests to internal IP addresses by using a specially crafted HTTP endpoint.

MEDIUM 4.3EPSS 0.70%

Does this matter?

Lower severity and a low EPSS score (0.70%). Track it; it rarely justifies an emergency change on its own.

Description

Symbolicator is a symbolication service for native stacktraces and minidumps with symbol server support. An attacker could make Symbolicator send arbitrary GET HTTP requests to internal IP addresses by using a specially crafted HTTP endpoint. The response could be reflected to the attacker if they have an account on Sentry instance. The issue has been fixed in the release 23.11.2.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
0.70% probability · 51th percentile
CISA KEV
Not listed
Weakness
CWE-918
Affected
sentry/symbolicator
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.