CVE-2024-22873: Tencent Blueking Configuration Management Database

High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery (SSRF) via the event subscription function (/service/subscription.go). This vulnerability allows attackers to access internal requests via a crafted POST request.

Affected products

  • Tencent Blueking Configuration Management Database: from 3.2.2, up to and including 3.9.47

Published 2024-02-26. Last modified 2026-07-09.