6.3 MEDIUM
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): Low (L)
- Vulnerable System Impact Integrity (VI): None (N)
- Vulnerable System Impact Availability (VA): None (N)
- Subsequent System Impact Confidentiality (SC): High (H)
- Subsequent System Impact Integrity (SI): Low (L)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
- Modified Vulnerable System Impact Integrity (MVI): None (N)
- Modified Vulnerable System Impact Availability (MVA): None (N)
- Modified Subsequent System Impact Confidentiality (MSC): High (H)
- Modified Subsequent System Impact Integrity (MSI): Low (L)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse dismissed (not in Nixpkgs)
Pinpoint - Server-Side Request Forgery via Alarm Webhook Registration
Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook registration endpoint that allows authenticated users to register internal URLs due to missing SSRF protection. Attackers can trigger alarm threshold breaches to force the server to issue POST requests to internal hosts and metadata endpoints, enabling unauthorized access to internal network resources.
References
-
Researcher Disclosure issue-tracking
-
https://www.vulncheck.com/advisories/pinpoint-server-side-request-forgery-via-a… third-party-advisory
Affected products
- =<3.1.0
Matching in nixpkgs
pkgs.pinpoint
Tool for making hackers do excellent presentations
pkgs.haskellPackages.amazonka-pinpoint
Amazon Pinpoint SDK
-
nixos-unstable 2.0-unstable-2025-04-16
- nixpkgs-unstable 2.0-unstable-2025-04-16
- nixos-unstable-small 2.0-unstable-2025-04-16
-
nixos-26.05 2.0-unstable-2025-04-16
- nixos-26.05-small 2.0-unstable-2025-04-16
- nixpkgs-26.05-darwin 2.0-unstable-2025-04-16
pkgs.python312Packages.mypy-boto3-pinpoint
None
pkgs.python313Packages.mypy-boto3-pinpoint
Type annotations for boto3 pinpoint
pkgs.python314Packages.mypy-boto3-pinpoint
Type annotations for boto3 pinpoint
pkgs.haskellPackages.amazonka-pinpoint-email
Amazon Pinpoint Email Service SDK
-
nixos-unstable 2.0-unstable-2025-04-16
- nixpkgs-unstable 2.0-unstable-2025-04-16
- nixos-unstable-small 2.0-unstable-2025-04-16
-
nixos-26.05 2.0-unstable-2025-04-16
- nixos-26.05-small 2.0-unstable-2025-04-16
- nixpkgs-26.05-darwin 2.0-unstable-2025-04-16
pkgs.haskellPackages.amazonka-pinpoint-sms-voice
Amazon Pinpoint SMS and Voice Service SDK
-
nixos-unstable 2.0-unstable-2025-04-16
- nixpkgs-unstable 2.0-unstable-2025-04-16
- nixos-unstable-small 2.0-unstable-2025-04-16
-
nixos-26.05 2.0-unstable-2025-04-16
- nixos-26.05-small 2.0-unstable-2025-04-16
- nixpkgs-26.05-darwin 2.0-unstable-2025-04-16
pkgs.python313Packages.mypy-boto3-pinpoint-email
Type annotations for boto3 pinpoint-email
pkgs.python314Packages.mypy-boto3-pinpoint-email
Type annotations for boto3 pinpoint-email
pkgs.python313Packages.types-aiobotocore-pinpoint
Type annotations for aiobotocore pinpoint
pkgs.haskellPackages.amazonka-pinpoint-sms-voice-v2
Amazon Pinpoint SMS Voice V2 SDK
-
nixos-unstable 2.0-unstable-2025-04-16
- nixpkgs-unstable 2.0-unstable-2025-04-16
- nixos-unstable-small 2.0-unstable-2025-04-16
-
nixos-26.05 2.0-unstable-2025-04-16
- nixos-26.05-small 2.0-unstable-2025-04-16
- nixpkgs-26.05-darwin 2.0-unstable-2025-04-16
pkgs.python313Packages.mypy-boto3-pinpoint-sms-voice
Type annotations for boto3 pinpoint-sms-voice
pkgs.python314Packages.mypy-boto3-pinpoint-sms-voice
Type annotations for boto3 pinpoint-sms-voice
pkgs.python313Packages.mypy-boto3-pinpoint-sms-voice-v2
Type annotations for boto3 pinpoint-sms-voice-v2
pkgs.python313Packages.types-aiobotocore-pinpoint-email
Type annotations for aiobotocore pinpoint-email
pkgs.python314Packages.mypy-boto3-pinpoint-sms-voice-v2
Type annotations for boto3 pinpoint-sms-voice-v2
pkgs.python313Packages.types-aiobotocore-pinpoint-sms-voice
Type annotations for aiobotocore pinpoint-sms-voice
Package maintainers
-
@pSub Pascal Wittmann <mail@pascal-wittmann.de>
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>