Fedora Account System
Red Hat Associate
Red Hat Customer
In WhatsUp Gold versions released before 2023.1.2 , a blind SSRF vulnerability exists in Whatsup Gold's FaviconController that allows an attacker to send arbitrary HTTP requests on behalf of the vulnerable server. https://community.progress.com/s/article/Announcing-WhatsUp-Gold-v2023-1-2 https://www.progress.com/network-monitoring
Created whatsup tracking bugs for this issue: Affects: epel-7 [bug 2280523] Affects: fedora-38 [bug 2280524] Affects: fedora-39 [bug 2280525] Affects: fedora-40 [bug 2280526]