CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Proxmox 3Proxmox Mail Gateway Pve Http ServerVirtual EnvironmentApr 24, 2025 Dec 4, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) are vulnerable to SSRF when proxying HTTP requests between pve(pmg)proxy and pve(pmg)daemon. An attacker with an unprivileged account can craft an HTTP req...Show more |
1Proxmox 3Proxmox Mail Gateway Pve Http ServerVirtual EnvironmentApr 24, 2025 Dec 4, 2022 N/A· v4 7.1 HIGH· v3 N/A· v2 A response-header CRLF injection vulnerability in the Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) web interface allows a remote attacker to set cookies for a victim's browser that are longer than the...Show more |