Menu

#769 SSRF patch bypass in latest version (4.7.7)

4.7.7
closed-fixed
7
2021-02-22
2020-11-11
Gus Ralph
No

The latest version of Adminer can be abused as a HTTP client by using the ClickHouse driver.

The current fix for the SSRF issue is a simple check that verifies if the specified port is a privileged one.

This can be bypassed by using URL comments, or even slashes. For example, if you set the server parameter to:
"localhost:80#"
It will bypass the check, and allow for the malicious actor to hit internal, privileged ports.

Discussion

  • Jakub Vrána

    Jakub Vrána - 2020-12-06
    • status: open --> closed-fixed
     
  • Jakub Vrána

    Jakub Vrána - 2020-12-06

    Fixed, thanks.

     
  • Jakub Vrána

    Jakub Vrána - 2021-02-22
    • private: Yes --> No
     

Log in to post a comment.

MongoDB Logo MongoDB