CVE-2021-41792

CVE-2021-41792

An issue was discovered in Hyland org.alfresco:alfresco-content-services through 6.2.2.18 and org.alfresco:alfresco-transform-services through 1.3. A crafted HTML file, once uploaded, could trigger an unexpected request by the transformation engine. The response to the request is not available to the attacker, i.e., this is blind SSRF.

Source: CVE-2021-41792

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다