CVE-2021-41792

MEDIUM

Alfresco Content Services < 5.2.7.11 - SSRF

Title source: rule
STIX 2.1

Description

An issue was discovered in Hyland org.alfresco:alfresco-content-services through 6.2.2.18 and org.alfresco:alfresco-transform-services through 1.3. A crafted HTML file, once uploaded, could trigger an unexpected request by the transformation engine. The response to the request is not available to the attacker, i.e., this is blind SSRF.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://www.themissinglink.com.au/

Scores

CVSS v3 5.3
EPSS 0.0020
EPSS Percentile 41.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-918
Status published
Products (2)
alfresco/alfresco_content_services 5.0.0.0 - 5.2.7.11
alfresco/alfresco_transform_services < 1.3
Published Oct 21, 2021
Tracked Since Feb 18, 2026