PT-2025-30343 · Manager Io · Imanager
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Manager-io/Manager versions prior to 25.7.21.2525
Description
An unauthenticated full read Server-Side Request Forgery (SSRF) issue exists in the proxy handler component. This allows an attacker to bypass network isolation and access restrictions, potentially enabling access to internal services, cloud metadata endpoints, and the exfiltration of sensitive data from isolated network segments via the 'proxy' endpoint.
Recommendations
Update to version 25.7.21.2525.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Imanager