PT-2022-16930 · Unknown · Flyteconsole
Ehsandeep
·
Published
2022-05-17
·
Updated
2022-05-27
·
CVE-2022-24856
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
FlyteConsole versions prior to 0.52.0
Description
The issue concerns server-side request forgery (SSRF) when FlyteConsole is exposed to the general internet. An attacker can exploit this to access internal metadata servers or other unauthenticated URLs, potentially leading to the passing of headers to unauthorized actors.
Recommendations
For FlyteConsole versions prior to 0.52.0, update to version 0.52.0, which includes a patch that deletes the entire
cors proxy as it is no longer required for the console.
As a temporary workaround, consider disabling FlyteConsole's availability on the internet to minimize the risk of exploitation.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flyteconsole