CVE Vulnerabilities

CVE-2023-45195

Server-Side Request Forgery (SSRF)

Published: Jun 24, 2024 | Modified: Jun 25, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Adminer and AdminerEvo are vulnerable to SSRF via database connection fields. This could allow an unauthenticated remote attacker to enumerate or access systems the attacker would not otherwise have access to. Adminer is no longer supported, but this issue was fixed in AdminerEvo version 4.8.4.

Weakness

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Affected Software

Name Vendor Start Version End Version
Adminer Ubuntu esm-apps/bionic *
Adminer Ubuntu esm-apps/focal *
Adminer Ubuntu esm-apps/jammy *
Adminer Ubuntu esm-apps/noble *
Adminer Ubuntu esm-apps/xenial *
Adminer Ubuntu focal *
Adminer Ubuntu jammy *
Adminer Ubuntu mantic *
Adminer Ubuntu noble *

References