CVE-2017-18638
Publication date 11 October 2019
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
send_email in graphite-web/webapp/graphite/composer/views.py in Graphite through 1.1.5 is vulnerable to SSRF. The vulnerable SSRF endpoint can be used by an attacker to have the Graphite web server request any resource. The response to this SSRF request is encoded into an image file and then sent to an e-mail address that can be supplied by the attacker. Thus, an attacker can exfiltrate any information.
From the Ubuntu Security Team
It was discovered that Graphite insecurely handled certain crafted input on the send_email functionality. A remote attacker could possibly use this issue to exfiltrate sensitive information, resulting in a SSRF attack.
Status
Package | Ubuntu Release | Status |
---|---|---|
graphite-web | ||
22.04 LTS jammy |
Not affected
|
|
20.04 LTS focal |
Not affected
|
|
18.04 LTS bionic |
Fixed 1.0.2+debian-2ubuntu0.1~esm1
|
|
16.04 LTS xenial |
Fixed 0.9.15+debian-1ubuntu0.1~esm1
|
|
14.04 LTS trusty |
Fixed 0.9.12+debian-3ubuntu0.1~esm1
|
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu ProSeverity score breakdown
Parameter | Value |
---|---|
Base score | 7.5 · High |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | None |
Availability impact | None |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
References
Related Ubuntu Security Notices (USN)
- USN-6243-1
- Graphite-Web vulnerabilities
- 25 July 2023
Other references
- https://github.com/graphite-project/graphite-web/issues/2008
- https://github.com/graphite-project/graphite-web/pull/2499
- https://blog.orange.tw/2017/07/how-i-chained-4-vulnerabilities-on.html#second-bug-internal-graphite-ssrf
- https://github.com/graphite-project/graphite-web/security/advisories/GHSA-vfj6-275q-4pvm
- https://www.youtube.com/watch?v=ds4Gp4xoaeA
- https://www.cve.org/CVERecord?id=CVE-2017-18638