Description
The Spinnaker template resolution functionality is vulnerable to Server-Side Request Forgery (SSRF), which allows an attacker to send requests on behalf of Spinnaker potentially leading to sensitive data disclosure.
Remediation
References
https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2020-003.md
Related Vulnerabilities
CVE-2022-25855 Vulnerability in npm package create-choo-app3
CVE-2020-28500 Vulnerability in maven package org.webjars.bowergithub.lodash:lodash
CVE-2023-31581 Vulnerability in maven package com.usthe.sureness:sureness-core
CVE-2022-23307 Vulnerability in maven package org.apache.logging.log4j:log4j
CVE-2023-40037 Vulnerability in maven package org.apache.nifi:nifi-jms-processors