Server-Side Request Forgery in Spinnaker Orca
High severity
GitHub Reviewed
Published
May 7, 2021
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Package
Affected versions
< 8.7.0
Patched versions
8.7.0
Description
Published by the National Vulnerability Database
Aug 28, 2020
Reviewed
May 5, 2021
Published to the GitHub Advisory Database
May 7, 2021
Last updated
Feb 1, 2023
The Spinnaker template resolution functionality is vulnerable to Server-Side Request Forgery (SSRF), which allows an attacker to send requests on behalf of Spinnaker potentially leading to sensitive data disclosure.
References