High severity8.6NVD Advisory· Published Apr 12, 2021· Updated Jun 17, 2026
CVE-2021-29357
CVE-2021-29357
Description
The ECT Provider component in OutSystems Platform Server 10 before 10.0.1104.0 and 11 before 11.9.0 (and LifeTime management console before 11.7.0) allows SSRF for arbitrary outbound HTTP requests.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:outsystems:lifetime_management_console:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:outsystems:lifetime_management_console:*:*:*:*:*:*:*:*range: >=11,<11.7.0
- (no CPE)range: <11.7.0
cpe:2.3:a:outsystems:platform_server:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:outsystems:platform_server:*:*:*:*:*:*:*:*range: >=11,<11.9.0
- (no CPE)range: <10.0.1104.0, <11.9.0
- OutSystems/Platform Serverdescription
Patches
Vulnerability mechanics
References
2- labs.integrity.pt/advisories/cve-2021-29357/nvdThird Party Advisory
- success.outsystems.com/Support/Security/Vulnerabilities/Vulnerability_RTAF-2226nvdVendor Advisory
News mentions
0No linked articles in our index yet.