Vulnerabilities > CVE-2019-9187 - Server-Side Request Forgery (SSRF) vulnerability in Ikiwiki

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
ikiwiki
CWE-918
nessus

Summary

ikiwiki before 3.20170111.1 and 3.2018x and 3.2019x before 3.20190228 allows SSRF via the aggregate plugin. The impact also includes reading local files via file: URIs.

Vulnerable Configurations

Part Description Count
Application
Ikiwiki
230

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-4399.NASL
    descriptionJoey Hess discovered that the aggregate plugin of the Ikiwiki wiki compiler was susceptible to server-side request forgery, resulting in information disclosure or denial of service.
    last seen2020-06-01
    modified2020-06-02
    plugin id122518
    published2019-03-01
    reporterThis script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/122518
    titleDebian DSA-4399-1 : ikiwiki - security update
  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DLA-1716.NASL
    descriptionThe ikiwiki maintainers discovered that the aggregate plugin did not use LWPx::ParanoidAgent. On sites where the aggregate plugin is enabled, authorized wiki editors could tell ikiwiki to fetch potentially undesired URIs even if LWPx::ParanoidAgent was installed : local files via file: URIs other URI schemes that might be misused by attackers, such as gopher: hosts that resolve to loopback IP addresses (127.x.x.x) hosts that resolve to RFC 1918 IP addresses (192.168.x.x etc.) This could be used by an attacker to publish information that should not have been accessible, cause denial of service by requesting
    last seen2020-06-01
    modified2020-06-02
    plugin id122928
    published2019-03-19
    reporterThis script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/122928
    titleDebian DLA-1716-1 : ikiwiki security update