Description
The Spinnaker template resolution functionality is vulnerable to Server-Side Request Forgery (SSRF), which allows an attacker to send requests on behalf of Spinnaker potentially leading to sensitive data disclosure.
Remediation
References
https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2020-003.md
Related Vulnerabilities
CVE-2021-3765 Vulnerability in npm package validator
CVE-2020-7598 Vulnerability in maven package org.webjars.npm:minimist
CVE-2023-49804 Vulnerability in npm package uptime-kuma
CVE-2021-3780 Vulnerability in npm package peertube
CVE-2020-36282 Vulnerability in maven package com.rabbitmq.jms:rabbitmq-jms