Loading HuntDB...

GHSA-3qx3-xhmf-4jcc

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details


A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user to upload arbitrary content, potentially altering configuration. This is possible through the certificate validation functionality where the API accepts uploaded content and doesn't parse for invalid data

Related CVEs

Key Information

GHSA ID
GHSA-3qx3-xhmf-4jcc
Published
November 29, 2023 9:30 AM
Last Modified
November 29, 2023 9:30 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 30, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.