vendor:
Cortex
by:
Alexandre Basquin
7.7
CVSS
HIGH
Server-Side Request Forgery
918
CWE
Product Name: Cortex
Affected Version From: Cortex <= 2.1.3
Affected Version To: Cortex <= 2.1.3
Patch Exists: YES
Related CWE: CVE-2019-7652
CPE: a:thehive-project:cortex
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Tested on: 2.1.3
2019
Cortex Unshortenlink Analyzer < 1.1 - Server-Side Request Forgery
The 'UnshortenLink_1_0' analyzer used by Cortex contains an SSRF vulnerability. To exploit this vulnerability, a user must create a new analysis, select Data Type 'URL', and put an SSRF payload in the Data parameter. The result can be seen in the main dashboard.
Mitigation:
The issue has been fixed in UnshortenLink 1.1 released within Cortex-analyzers 1.15.2