Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests (such as GET) to interfaces such as localhost by using the Identity header. This is fixed in 16.25.2, 18.11.2, and 19.3.2.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Asterisk 代码问题漏洞
Vulnerability Description
Asterisk是一款PBX系统的软件,运行在Linux系统上,支持使用SIP、IAX、H323协议进行IP通话。 Asterisk 19.x 版本及之前版本 STIR/SHAKEN 存在安全漏洞,该漏洞源于可以使用 Identity 标头向 localhost 等接口发送任意请求(例如 GET)。该问题在 16.25.2、18.11.2 和 19.3.2 中已修复。
CVSS Information
N/A
Vulnerability Type
N/A