CVE-2021-22969
Server-Side Request Forgery in Concrete CMS
EPSS 0.83%
Description
Concrete CMS (formerly concrete5) versions below 8.5.7 has a SSRF mitigation bypass using DNS Rebind attack giving an attacker the ability to fetch cloud IAAS (ex AWS) IAM keys.To fix this Concrete CMS no longer allows downloads from the local network and specifies the validated IP when downloading rather than relying on DNS.Discoverer.
How to fix CVE-2021-22969
To remediate CVE-2021-22969, upgrade the affected package to a fixed version below.
- Packagist/concrete5/core—upgrade to 8.5.7 or later
Is CVE-2021-22969 being exploited?
Low — EPSS is 0.8%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 8.5.7