CVE-2022-41412
About
An issue in the graphData.cgi component of perfSONAR v4.4.5 and prior allows attackers to access sensitive data and execute Server-Side Request Forgery (SSRF) attacks.
Rainforest analyst review
perfSONAR's graphData.cgi component lets an attacker reach sensitive data and, more importantly, drive server-side request forgery, unauthenticated and over the network. The scope-changed metric is the tell: the SSRF lets the perfSONAR host make requests to systems beyond itself, so the affected blast radius extends past the vulnerable component into whatever internal services it can touch.
perfSONAR is network-measurement software that lives on research, education, and backbone networks, often on well-connected hosts with broad internal reach, which is precisely what makes an SSRF here valuable. An attacker uses it to enumerate and hit internal infrastructure and metadata services from a trusted vantage point. It is confidentiality-oriented rather than a direct takeover, but as a pivot it can be the opening move of a deeper intrusion.
The determining factor for us is reachability, both inbound and outbound. We want to know which perfSONAR nodes expose graphData.cgi to untrusted networks and, just as critically, what those nodes can reach internally, because tightening egress and segmenting the measurement hosts limits the SSRF's usefulness even before the component is fixed. Exposure mapping is where this one gets prioritized up or down.
References
Related CVEs
Frequently asked questions
What is CVE-2022-41412?
An issue in the graphData.cgi component of perfSONAR v4.4.5 and prior allows attackers to access sensitive data and execute Server-Side Request Forgery (SSRF) attacks.
How severe is CVE-2022-41412?
CVE-2022-41412 carries a CVSS 3.1 base score of 8.6, rated high. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 86 out of 100, in the critical band.
How is CVE-2022-41412 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity None and availability None.
Which products are affected by CVE-2022-41412?
Public advisories list the following as affected: perfsonar. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2022-41412?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
