Record summary

CVE-2021-44139 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Sentinel 1.8.2 is vulnerable to Server-side request forgery (SSRF).

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHAlibaba Sentinel - Server-side request forgery (SSRF)CVSS 7.5

There is a Pre-Auth SSRF vulnerability in Alibaba Sentinel version 1.8.2, which allows remote unauthenticated attackers to perform SSRF attacks via the /registry/machine endpoint through the ip parameter.

Impact

Successful exploitation of this vulnerability could allow an attacker to send crafted requests from the server, potentially leading to unauthorized access to internal resources or network scanning.

Remediation

Apply the latest security patches or updates provided by Alibaba Sentinel to fix the SSRF vulnerability (CVE-2021-44139).

WeaknessesCWE-918
AuthorsDhiyaneshDK
Template tagscve2021cvessrfalibabaoastmisconfigsentinelhashicorpvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:hashicorp:sentinel:1.8.2:*:*:*:*:*:*:*
Shodan: title:"Sentinel Dashboard"
Shodan: http.title:"sentinel dashboard"
FOFA: title="sentinel dashboard"
Google: intitle:"sentinel dashboard"

Source: ProjectDiscovery

References

2