CVE-2021-44139
Alibaba Sentinel - Server-side request forgery (SSRF)
Record summary
CVE-2021-44139 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
Sentinel 1.8.2 is vulnerable to Server-side request forgery (SSRF).
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHAlibaba Sentinel - Server-side request forgery (SSRF)CVSS 7.5
There is a Pre-Auth SSRF vulnerability in Alibaba Sentinel version 1.8.2, which allows remote unauthenticated attackers to perform SSRF attacks via the /registry/machine endpoint through the ip parameter.
Impact
Successful exploitation of this vulnerability could allow an attacker to send crafted requests from the server, potentially leading to unauthorized access to internal resources or network scanning.
Remediation
Apply the latest security patches or updates provided by Alibaba Sentinel to fix the SSRF vulnerability (CVE-2021-44139).
Source: ProjectDiscovery