CVE-2024-22217

A Server-Side Request Forgery (SSRF) vulnerability in Terminalfour before 8.3.19 allows authenticated users to use specific features to access internal services including sensitive information on the server that Terminalfour runs on.
Configurations

Configuration 1 (hide)

cpe:2.3:a:terminalfour:terminalfour:*:*:*:*:*:*:*:*

History

11 Sep 2024, 13:19

Type Values Removed Values Added
References () https://docs.terminalfour.com/release-notes/security-notices/cve-2024-22217/ - () https://docs.terminalfour.com/release-notes/security-notices/cve-2024-22217/ - Release Notes
References () https://docs.terminalfour.com/articles/release-notes-highlights/ - () https://docs.terminalfour.com/articles/release-notes-highlights/ - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-918
CPE cpe:2.3:a:terminalfour:terminalfour:*:*:*:*:*:*:*:*
First Time Terminalfour
Terminalfour terminalfour

15 Aug 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-15 18:15

Updated : 2025-03-24 17:15


NVD link : CVE-2024-22217

Mitre link : CVE-2024-22217


JSON object : View

Products Affected

terminalfour

  • terminalfour
CWE
CWE-918

Server-Side Request Forgery (SSRF)