PT-2019-20061 · Terria · Terriajs-Server
Published
2019-05-29
·
Updated
2019-05-29
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
terriajs-server versions prior to 2.7.4
Description
The issue allows for Server-Side Request Forgery (SSRF) under specific conditions. If an attacker has access to a server whitelisted by the terriajs-server proxy, or if they can modify the DNS records of a whitelisted domain, they can exploit the terriajs-server proxy to access any HTTP-accessible resources available to the server. This includes private resources within the hosting environment.
Recommendations
Upgrade to version 2.7.4 or later.
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Terriajs-Server