Description Preview
A Server Side Request Forgery (SSRF) vulnerability (CWE-918) was discovered in Deskpro Support Desk version 2021.21.6. This vulnerability allows attackers to execute arbitrary code by sending specially crafted URLs to the server. When exploited, the vulnerability enables attackers to make requests from the server to internal or external resources, potentially accessing sensitive information or services that should not be publicly accessible.
Overview
The vulnerability exists in Deskpro Support Desk v2021.21.6, a customer support platform. The SSRF vulnerability allows attackers to manipulate the server into making requests to arbitrary destinations. This could lead to unauthorized access to internal resources, data exfiltration, or even remote code execution in certain circumstances. The vulnerability is particularly dangerous as it may allow attackers to bypass network security controls by leveraging the trusted position of the Deskpro server within the network.
Remediation
Organizations using Deskpro Support Desk should:
- Update to the latest version of Deskpro Support Desk that contains patches for this vulnerability.
- Implement network-level restrictions to limit the server's ability to make outbound connections to unauthorized destinations.
- Deploy a web application firewall (WAF) to help detect and block SSRF attack attempts.
- Regularly audit server logs for suspicious activities that might indicate exploitation attempts.
- Follow the principle of least privilege for service accounts running the application.
- Consider implementing additional input validation and URL whitelisting for all user-supplied URLs.
References
- Product information: http://deskpro.com
- Detailed exploit information: https://sayaanalam.github.io/CVE-2021-35391.html
- CWE-918: Server-Side Request Forgery (SSRF) - https://cwe.mitre.org/data/definitions/918.html
Industry ExposureMost to leastThis section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
- Accommodation & Food ServicesAccommodation & Food Services
- Administrative, Support, Waste Management & Remediation ServicesAdministrative, Support, Waste Management & Remediation Services
- Agriculture, Forestry Fishing & HuntingAgriculture, Forestry Fishing & Hunting
- Arts, Entertainment & RecreationArts, Entertainment & Recreation
- ConstructionConstruction
- Educational ServicesEducational Services
- Finance and InsuranceFinance and Insurance
- Health Care & Social AssistanceHealth Care & Social Assistance
- InformationInformation
- Management of Companies & EnterprisesManagement of Companies & Enterprises
- ManufacturingManufacturing
- MiningMining
- Other Services (except Public Administration)Other Services (except Public Administration)
- Professional, Scientific, & Technical ServicesProfessional, Scientific, & Technical Services
- Public AdministrationPublic Administration
- Real Estate Rental & LeasingReal Estate Rental & Leasing
- Retail TradeRetail Trade
- Transportation & WarehousingTransportation & Warehousing
- UtilitiesUtilities
- Wholesale TradeWholesale Trade