« Volver al listado

CVE-2024-2796

Estado: AplazadaCrítica (9.3)—

A server-side request forgery (SSRF) was discovered in the Akana API Platform in versions prior to and including 2022.1.3. Reported by Jakob Antonsson.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-2796",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-2796",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-07T19:12:07.968499Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@puppet.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 9.3,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4.7,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@puppet.com",
      "affectedData": [
        {
          "vendor": "Akana",
          "product": "Akana API Platform",
          "versions": [
            {
              "status": "affected",
              "version": "2022.1.1",
              "lessThan": "2022.1.1 (CVE-2024-2796 Patch)",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "2022.1.2",
              "lessThan": "2022.1.2 (CVE-2024-2796 Patch)",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "0.0.0",
              "lessThan": "2024.1.0",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "0.0.0",
              "lessThan": "2022.1.3.2",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:akana:akana_api_platform:*:*:*:*:*:*:*:*"
          ],
          "vendor": "akana",
          "product": "akana_api_platform",
          "versions": [
            {
              "status": "affected",
              "version": "2022.1.1",
              "lessThan": "2022.1.1",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "2022.1.2",
              "lessThan": "2022.1.2",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "2022.1.3",
              "lessThan": "2022.1.3",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "0.0.0",
              "lessThan": "2024.1.0",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-04-18T15:15:29.857",
  "references": [
    {
      "url": "https://portal.perforce.com/s/detail/a91PA000001STuXYAW",
      "source": "security@puppet.com"
    },
    {
      "url": "https://portal.perforce.com/s/detail/a91PA000001STuXYAW",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@puppet.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-918"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A server-side request forgery (SSRF) was discovered in the Akana API Platform in versions prior to and including 2022.1.3. Reported by Jakob Antonsson."
    },
    {
      "lang": "es",
      "value": "Se descubrió server-side request forgery (SSRF) en Akana Community Manager Developer Portal en versiones anteriores a la 2022.1.3 incluida. Reportado por Jakob Antonsson."
    }
  ],
  "lastModified": "2026-06-17T07:25:34.180",
  "sourceIdentifier": "security@puppet.com"
}