Description
The Spinnaker template resolution functionality is vulnerable to Server-Side Request Forgery (SSRF), which allows an attacker to send requests on behalf of Spinnaker potentially leading to sensitive data disclosure.
Remediation
References
https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2020-003.md
Related Vulnerabilities
CVE-2022-23541 Vulnerability in maven package org.webjars.npm:jsonwebtoken
CVE-2020-10693 Vulnerability in maven package org.hibernate:hibernate-validator
CVE-2022-2932 Vulnerability in maven package org.webjars.npm:mobiledoc-kit
CVE-2022-3510 Vulnerability in maven package com.google.protobuf:protobuf-java
CVE-2020-26256 Vulnerability in maven package org.webjars.npm:fast-csv