CVE-2024-22873: Tencent Blueking Configuration Management Database
High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.
Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery (SSRF) via the event subscription function (/service/subscription.go). This vulnerability allows attackers to access internal requests via a crafted POST request.
Affected products
- Tencent Blueking Configuration Management Database: from 3.2.2, up to and including 3.9.47
Published 2024-02-26. Last modified 2026-07-09.