[ubuntu-hardened] CVE-2022-45152

Marcos Alano marcoshalano at gmail.com
Tue Jul 30 18:23:20 UTC 2024


BTW, if you want mitigations fo blind SRRF vulnerabilities in general, 
you could ask ChatGPT. I used the prompt "what is a workaround to a 
blind srrf vulnerability?" and returned many things, but I think the 
most important thing is to configure an allow list and maybe a deny 
lists (including block "localhost").

On 29/07/2024 03:41, Arun Joshi wrote:
> 
> To add here , Apache Web application is vulnerable to blind SSRF where 
> it is possible to perform port scanning on the internal server IP i.e, 
> host machine (localhost or 127.0.0.1)
> 
> On Mon, 29 Jul 2024, 11:56 Arun Joshi, <joshiarunkumar1 at gmail.com 
> <mailto:joshiarunkumar1 at gmail.com>> wrote:
> 
>     Hi team,
> 
>     Please provide steps to mitigate/path Ubuntu 22.04 LTS for blind
>     SSRF , CVE-2022-45152.
> 
>     Your response is highly appreciated.
> 
>     Regards
>     Arun Joshi
> 

-- 
Marcos Alano




More information about the ubuntu-hardened mailing list