Description
The Spinnaker template resolution functionality is vulnerable to Server-Side Request Forgery (SSRF), which allows an attacker to send requests on behalf of Spinnaker potentially leading to sensitive data disclosure.
Remediation
References
https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2020-003.md
Related Vulnerabilities
CVE-2022-31129 Vulnerability in maven package org.webjars:momentjs
CVE-2017-16008 Vulnerability in maven package org.webjars:i18next
CVE-2023-48711 Vulnerability in maven package org.webjars.npm:google-translate-api-browser
CVE-2016-10531 Vulnerability in maven package org.webjars.bower:marked
CVE-2020-28277 Vulnerability in maven package org.webjars.npm:dset