IT

Tracker / CVE-2021-21009

CVE-2021-21009

High 8.6

Adobe Campaign Classic Gold Standard 10 (and earlier), 20.3.1 (and earlier), 20.2.3 (and earlier), 20.1.3 (and earlier), 19.2.3 (and earlier) and 19.1.7 (and earlier) are affected by a server-side request forgery (SSRF) vulnerability. Successful exploitation could allow an attacker to use the Campaign instance to issue unauthorized requests to internal or external resources.

Affected products and versions

adobe campaign · … → 19.1.8
adobe campaign · 19.2 → 19.2.4
adobe campaign · 20.1 → 20.1.4
adobe campaign · 20.2 → 20.2.4
adobe campaign · 20.3 → 20.3.3

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References