Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xr9h-9m79-x29g

Опубликовано: 01 мар. 2021
Источник: github
Github: Прошло ревью

Описание

SSRF in Rendertron

Rendertron versions prior to 3.0.0 are are susceptible to a Server-Side Request Forgery (SSRF) attack. An attacker can use a specially crafted webpage to force a rendertron headless chrome process to render internal sites it has access to, and display it as a screenshot. Suggested mitigations are to upgrade your rendertron to version 3.0.0, or, if you cannot update, to secure the infrastructure to limit the headless chrome's access to your internal domain.

Пакеты

Наименование

rendertron

npm
Затронутые версииВерсия исправления

< 3.0.0

3.0.0

EPSS

Процентиль: 18%
0.00057
Низкий

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 3.5
nvd
почти 5 лет назад

Rendertron versions prior to 3.0.0 are are susceptible to a Server-Side Request Forgery (SSRF) attack. An attacker can use a specially crafted webpage to force a rendertron headless chrome process to render internal sites it has access to, and display it as a screenshot. Suggested mitigations are to upgrade your rendertron to version 3.0.0, or, if you cannot update, to secure the infrastructure to limit the headless chrome's access to your internal domain.

EPSS

Процентиль: 18%
0.00057
Низкий

Дефекты

CWE-918