CVE-2021-29357

The ECT Provider component in OutSystems Platform Server 10 before 10.0.1104.0 and 11 before 11.9.0 (and LifeTime management console before 11.7.0) allows SSRF for arbitrary outbound HTTP requests.
Configurations

Configuration 1

cpe:2.3:a:outsystems:lifetime_management_console:*:*:*:*:*:*:*:*
cpe:2.3:a:outsystems:platform_server:*:*:*:*:*:*:*:*
cpe:2.3:a:outsystems:outsystems:*:*:*:*:*:*:*:*

Information

Published : 2021-04-12 07:15

Updated : 2021-04-21 06:20


NVD link : CVE-2021-29357

Mitre link : CVE-2021-29357

Products Affected
No products.
CWE
CWE-918

Server-Side Request Forgery (SSRF)