CVE-2022-41412
perfsonar perfsonar Server-Side Request Forgery (SSRF)
Record summary
CVE-2022-41412 has a selected CVSS score of 8.6 (high); EIP currently links 1 Nuclei template.
Description
An issue in the graphData.cgi component of perfSONAR v4.4.5 and prior allows attackers to access sensitive data and execute Server-Side Request Forgery (SSRF) attacks.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 17, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 24, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
perfsonarBrowse perfsonar / perfsonar | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHperfSONAR 4.x <= 4.4.4 - Server-Side Request ForgeryCVSS 8.6
An issue in the graphData.cgi component of perfSONAR v4.4.5 and prior allows attackers to access sensitive data and execute Server-Side Request Forgery (SSRF) attacks.
Impact
Unauthenticated attackers can exploit SSRF vulnerabilities in the graphData.cgi component to access internal resources, bypass firewall restrictions, and potentially access sensitive performance measurement data from internal network monitoring systems.
Remediation
Upgrade to perfSONAR version 4.4.5 or later that validates and restricts URL parameters in the graphData.cgi component.
Source: ProjectDiscovery