PT-2022-16930 · Unknown · Flyteconsole

Ehsandeep

·

Published

2022-05-17

·

Updated

2022-05-27

·

CVE-2022-24856

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions FlyteConsole versions prior to 0.52.0
Description The issue concerns server-side request forgery (SSRF) when FlyteConsole is exposed to the general internet. An attacker can exploit this to access internal metadata servers or other unauthenticated URLs, potentially leading to the passing of headers to unauthorized actors.
Recommendations For FlyteConsole versions prior to 0.52.0, update to version 0.52.0, which includes a patch that deletes the entire cors proxy as it is no longer required for the console. As a temporary workaround, consider disabling FlyteConsole's availability on the internet to minimize the risk of exploitation.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24856
GHSA-WWW6-HF2V-V9M9

Affected Products

Flyteconsole