CVE-2020-12695 - log back

CVE-2020-12695 edited at 05 Dec 2020 19:40:05
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Proxy injection
Description
+ The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue. This issue could allow a device connected to the local network (i.e., a device that has been authorized to transmit packets in the network in which the AP is located) to trigger the AP to initiate a HTTP (TCP/IP) connection to an arbitrary URL, including connections to servers in external networks.
References
+ http://www.callstranger.com/
+ https://w1.fi/security/2020-1/upnp-subscribe-misbehavior-wps-ap.txt
+ https://w1.fi/security/2020-1/0001-WPS-UPnP-Do-not-allow-event-subscriptions-with-URLs-.patch
+ https://w1.fi/security/2020-1/0002-WPS-UPnP-Fix-event-message-generation-using-a-long-U.patch
+ https://w1.fi/security/2020-1/0003-WPS-UPnP-Handle-HTTP-initiation-failures-for-events-.patch
Notes
CVE-2020-12695 created at 05 Dec 2020 19:27:51