CVE-2022-26499
15.04.2022, 05:15
An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests (such as GET) to interfaces such as localhost by using the Identity header. This is fixed in 16.25.2, 18.11.2, and 19.3.2.
Vendor | Product | Version |
---|---|---|
digium | asterisk | 16.15.0 ≤ 𝑥 ≤ 16.25.1 |
digium | asterisk | 18.0 ≤ 𝑥 < 18.11.2 |
digium | asterisk | 19.0.0 ≤ 𝑥 ≤ 19.3.1 |
debian | debian_linux | 10.0 |
debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References