Total vulnerabilities in the database
An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests (such as GET) to interfaces such as localhost by using the Identity header. This is fixed in 16.25.2, 18.11.2, and 19.3.2.
Software | From | Fixed in |
---|---|---|
digium / asterisk | 19.0.0 | 19.3.1.x |
digium / asterisk | 16.15.0 | 16.25.1.x |
digium / asterisk | 18.0 | 18.11.2 |
debian / debian_linux | 10.0 | 10.0.x |
debian / debian_linux | 11.0 | 11.0.x |