PT-2019-20061 · Terria · Terriajs-Server

Published

2019-05-29

·

Updated

2019-05-29

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions terriajs-server versions prior to 2.7.4
Description The issue allows for Server-Side Request Forgery (SSRF) under specific conditions. If an attacker has access to a server whitelisted by the terriajs-server proxy, or if they can modify the DNS records of a whitelisted domain, they can exploit the terriajs-server proxy to access any HTTP-accessible resources available to the server. This includes private resources within the hosting environment.
Recommendations Upgrade to version 2.7.4 or later.

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-P72P-RJR2-R439

Affected Products

Terriajs-Server