Description
The Spinnaker template resolution functionality is vulnerable to Server-Side Request Forgery (SSRF), which allows an attacker to send requests on behalf of Spinnaker potentially leading to sensitive data disclosure.
Remediation
References
https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2020-003.md
Related Vulnerabilities
CVE-2020-16040 Vulnerability in maven package org.webjars.npm:electron
CVE-2020-28501 Vulnerability in npm package es6-crawler-detect
CVE-2023-38507 Vulnerability in npm package @strapi/plugin-users-permissions
CVE-2020-13959 Vulnerability in maven package org.apache.velocity.tools:velocity-tools-view