Description
Prior to 23.2, it is possible to perform arbitrary Server-Side requests via HTTP-based connectors within BeyondInsight, resulting in a server-side request forgery vulnerability.
Problem types
CWE-918 Server-Side Request Forgery (SSRF)
Product status
Any version before 23.2
Credits
Paolo Caminati
Daniele Montanaro
References
www.beyondtrust.com/trust-center/security-advisories/BT24-05
www.beyondtrust.com/trust-center/security-advisories/BT24-05