Описание
A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Attackers can perform an SSRF attack and steal cloud metadata service on AWS/GCP/Azure environment through foreman component.
Ссылки
- Vendor Advisory
- Vendor AdvisoryIssue Tracking
Уязвимые конфигурации
EPSS
4.4 Medium
CVSS3
Дефекты
Связанные уязвимости
A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Attackers can perform an SSRF attack and steal cloud metadata service on AWS/GCP/Azure environment through foreman component.
A flaw has been found in foreman when HTTP parameters are modified in ...
A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Attackers can perform an SSRF attack and steal cloud metadata service on AWS/GCP/Azure environment through foreman component.
EPSS
4.4 Medium
CVSS3