Skip to content

Instantly share code, notes, and snippets.

@exp1orer
exp1orer / gist:0f190c6a64b668a9b1c4c47789affa09
Created February 14, 2024 08:18
TencentBlueKing CMDB Server-side request forgery
[AFFECTED VERSION(S)]
- 3.2.x - 3.9.x
[DESCRIPTION]
Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery (SSRF) via the event subscription function (/service/subscription.go). This vulnerability allows attackers to access internal requests via a crafted POST request.