← Späť na vyhľadávanie CVE

CVE-2026-79659

Ech0

Popis

Ech0 before 4.7.3 contains a server-side request forgery vulnerability in the fetchPeerConnectInfo function that uses unvalidated HTTP requests instead of safe request methods with URL validation. Authenticated attackers can supply arbitrary URLs to access internal services and cloud metadata endpoints by triggering connection health checks or peer connection operations.

CVSS 7.7EPSS 0.209%Riziko 0.78
Zobraziť zdroj
Zverejnené
2026-08-25 12:16:29
Dotknuté verzie
<4.7.3
Typ
Webová aplikácia
Posledná úprava
2026-08-25 13:19:32
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N