<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:weaver:e_bridge:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aweavere_bridge/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 20:26:48 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aweavere_bridge/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Arbitrary File Read and SSRF Vulnerability in Weaver e-Bridge</title><link>https://feed.craftedsignal.io/briefs/2026-10-weaver-ebridge-arbitrary-file-read/</link><pubDate>Fri, 02 Oct 2026 20:26:48 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-weaver-ebridge-arbitrary-file-read/</guid><description>Weaver e-Bridge contains an unauthenticated arbitrary file read and SSRF vulnerability in the saveYZJFile endpoint, enabling attackers to access sensitive system files or scan internal network resources.</description><content:encoded><![CDATA[<p>Weaver e-Bridge contains a critical vulnerability (CVE-2020-37278) within its saveYZJFile endpoint that allows for both unauthenticated arbitrary file read and server-side request forgery (SSRF). By manipulating the downloadUrl parameter, a remote attacker can force the application to retrieve and expose local files, such as /etc/passwd, or leverage the server as a proxy to conduct SSRF attacks against internal network infrastructure. This vulnerability represents a significant risk for environments utilizing e-Bridge, as it facilitates credential theft, configuration leakage, and internal reconnaissance. Exploitation of this flaw has been observed in the wild since October 17, 2023, as documented by the Shadowserver Foundation. Defenders should prioritize patching and monitoring traffic directed toward the affected endpoint.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies an internet-facing instance of Weaver e-Bridge.</li>
<li>Attacker crafts an HTTP request targeting the saveYZJFile endpoint.</li>
<li>Attacker injects a file:// URI into the downloadUrl parameter to target local files (e.g., /etc/passwd).</li>
<li>The application processes the malicious parameter without sufficient input validation.</li>
<li>The server reads the content of the specified local file from the disk.</li>
<li>The server returns the contents of the file in the HTTP response body to the attacker.</li>
<li>Alternatively, the attacker injects an http(s):// URI into the downloadUrl parameter to probe internal services.</li>
<li>The server performs the request as the internal host, allowing the attacker to bypass network perimeter controls.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated remote attackers to read arbitrary files from the host filesystem, potentially leading to full system compromise through the exposure of configuration files, keys, and credentials. Furthermore, the SSRF capability enables attackers to pivot into the internal network, perform port scanning, and interact with internal-only web services that are otherwise unreachable from the internet.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Monitor web server access logs for anomalous requests to the saveYZJFile endpoint involving file:// or unexpected URL schemes in the downloadUrl parameter.</li>
<li>Deploy the provided Sigma rule to detect exploitation attempts against the vulnerable endpoint.</li>
<li>Patch affected Weaver e-Bridge instances immediately as updates become available from the vendor.</li>
<li>Restrict network access to the saveYZJFile endpoint at the firewall level if immediate patching is not possible.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>vulnerability</category><category>web-application</category><category>ssrf</category></item></channel></rss>