[ubuntu-hardened] CVE-2022-45152
Marcos Alano
marcoshalano at gmail.com
Tue Jul 30 18:23:20 UTC 2024
BTW, if you want mitigations fo blind SRRF vulnerabilities in general,
you could ask ChatGPT. I used the prompt "what is a workaround to a
blind srrf vulnerability?" and returned many things, but I think the
most important thing is to configure an allow list and maybe a deny
lists (including block "localhost").
On 29/07/2024 03:41, Arun Joshi wrote:
>
> To add here , Apache Web application is vulnerable to blind SSRF where
> it is possible to perform port scanning on the internal server IP i.e,
> host machine (localhost or 127.0.0.1)
>
> On Mon, 29 Jul 2024, 11:56 Arun Joshi, <joshiarunkumar1 at gmail.com
> <mailto:joshiarunkumar1 at gmail.com>> wrote:
>
> Hi team,
>
> Please provide steps to mitigate/path Ubuntu 22.04 LTS for blind
> SSRF , CVE-2022-45152.
>
> Your response is highly appreciated.
>
> Regards
> Arun Joshi
>
--
Marcos Alano
More information about the ubuntu-hardened
mailing list