CVE Vulnerabilities

CVE-2019-3996

Externally Controlled Reference to a Resource in Another Sphere

Published: Dec 17, 2019 | Modified: Nov 07, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

ELOG 3.1.4-57bea22 and below can be used as an HTTP GET request proxy when unauthenticated remote attackers send crafted HTTP POST requests.

Weakness

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

Affected Software

Name Vendor Start Version End Version
Elog Elog_project * 3.1.4-57bea22 (including)
Elog Ubuntu bionic *
Elog Ubuntu disco *
Elog Ubuntu eoan *
Elog Ubuntu groovy *
Elog Ubuntu hirsute *
Elog Ubuntu impish *
Elog Ubuntu trusty *
Elog Ubuntu xenial *

References