Description
The Spinnaker template resolution functionality is vulnerable to Server-Side Request Forgery (SSRF), which allows an attacker to send requests on behalf of Spinnaker potentially leading to sensitive data disclosure.
Remediation
References
https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2020-003.md
Related Vulnerabilities
CVE-2019-18212 Vulnerability in maven package org.lsp4xml:lsp4xml-extensions
CVE-2020-7639 Vulnerability in npm package eivindfjeldstad-dot
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa-nifi-parent
CVE-2020-12265 Vulnerability in npm package decompress
CVE-2022-35915 Vulnerability in npm package @openzeppelin/contracts-upgradeable