A verbose error handling issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request forgery. This issue only affects GravityZone Console versions before 6.38.1-5 running only on premise.
The proxy service in GravityZone Update Server exposes error information in excessive detail (CWE-209), enabling an attacker to manipulate server-side requests (CWE-918). Exploiting this vulnerability, an unauthenticated remote attacker can cause the server to execute HTTP requests to internal network resources. The attack is possible without user interaction, however it requires a certain level of complexity on the attacker's side (AC:H according to the CVSS vector).
An attacker can gain unauthorized access to internal network resources and services that are not directly accessible from outside, which may lead to disclosure of sensitive data or further compromise of system integrity and availability.
Bitdefender GravityZone Console should be updated to version 6.38.1-5 or newer. Detailed information is available in the official Bitdefender security advisory at the address indicated in the references.
Bitdefender GravityZone Console in versions before 6.38.1-5, operating only in on-premise mode (local installations). Cloud installations are not vulnerable.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XBitdefender Gravityzone
APPBitdefender< 6.38.1-5
Related vulnerabilities
Niebezpieczna deserializacja PHP w Bitdefender GravityZone Console (RCE)
Nieprawidłowa kontrola dostępu w API patchesUpdate — Bitdefender Endpoint Security Tools
Nieautoryzowany dostęp z uprawnieniami root w Bitdefender GravityZone VMware
Bitdefender GravityZone – pominięcie weryfikacji podpisu i RCE przez instalator
A host whitelist parser issue in the proxy service implemented in the GravityZone Update Server allows an atta...