Prior to 23.2, it is possible to perform arbitrary Server-Side requests via HTTP-based connectors within BeyondInsight, resulting in a server-side request forgery vulnerability.
2024-06-04T21:15:35.277
2024-11-21T09:42:24.783
Modified
13061848-ea10-403d-bd75-c83a022c2891
CVSSv3.1: 4.8 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | beyondtrust | beyondinsight | < 23.2 | Yes |