CVE-2024-12867 HIGH

CVE-2024-12867: Server-Side Request Forgery in Arctic Hub URL Mapper allows an unauthenticated remote attacker to exfiltrate and modify configurations and data

Vendor Arctic Security
Product Arctic Hub
Weakness CWE-918 · SSRF
Published December 20, 2024
Last update December 24, 2024

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:N/SI:L/SA:N/AU:N/R:U/V:C/RE:M/U:Amber

What the vulnerability does

01Description

Server-Side Request Forgery in URL Mapper in Arctic Security's Arctic Hub versions 3.0.1764-5.6.1877 allows an unauthenticated remote attacker to exfiltrate and modify configurations and data.

Key dates

02Disclosure timeline

December 20, 2024 CVE published
December 24, 2024 Record updated