U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-4642

Change History

CVE Rejected by huntr.dev 5/20/2024 1:15:09 PM

Action Type Old Value New Value

CVE Translated by huntr.dev 5/20/2024 1:15:09 PM

Action Type Old Value New Value
Removed Translation
Title: huntr.dev
Description: Existe una vulnerabilidad de Server Side Request Forgery (SSRF) en el repositorio wandb/wandb debido a un manejo inadecuado de las redirecciones HTTP 302. Este problema permite a los miembros del equipo con acceso a la función 'Configuración de usuario -> Webhooks' aprovechar esta vulnerabilidad para acceder a servidores HTTP internos. En casos graves, como en instancias de AWS, se podría abusar de esto para lograr la ejecución remota de código en la máquina de la víctima. La vulnerabilidad está presente en la última versión del repositorio.

								
						

CVE Modified by huntr.dev 5/20/2024 1:15:09 PM

Action Type Old Value New Value
Removed CVSS V3
huntr.dev AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

								
						
Removed CWE
huntr.dev CWE-918

								
						
Changed Description
A Server-Side Request Forgery (SSRF) vulnerability exists in the wandb/wandb repository due to improper handling of HTTP 302 redirects. This issue allows team members with access to the 'User settings -> Webhooks' function to exploit this vulnerability to access internal HTTP(s) servers. In severe cases, such as on AWS instances, this could potentially be abused to achieve remote code execution on the victim's machine. The vulnerability is present in the latest version of the repository.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Removed Reference
huntr.dev https://huntr.com/bounties/055eb540-57f8-46d6-b858-3a9e22d347d9