Description
The Ivanti Connect Secure, Policy Secure Gate and Neurons have an SSRF (server-side request forgery) vulnerability. An attacker can use this vulnerability to bypass the fix for the authentication bypass vulnerability (CVE-2023-46805) and exploit the RCE vulnerability (CVE-2024-21887) to compromise the system.
Remediation
Upgrade to the latest version of Ivanti Connect Secure / Policy Secure / Neurons
References
Related Vulnerabilities
Python CVE-2020-27619 Vulnerability (CVE-2020-27619)
Atlassian Jira URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2021-39112)
MediaWiki Other Vulnerability (CVE-2005-0535)
WordPress URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2019-16220)
PostgreSQL Resource Management Errors Vulnerability (CVE-2007-4772)