all-docs icon indicating copy to clipboard operation
all-docs copied to clipboard

Server-Side Request Forgery vulnerability

Open Redpeppersir opened this issue 1 year ago • 0 comments

The /auth/uploadByUrl endpoint allows a URL to be submitted for the server to access. An attacker can exploit this to send requests to the server, and a Server-Side Request Forgery (SSRF) vulnerability allows the attacker to manipulate the server into making requests, potentially leading to access to internal systems and leakage of sensitive information.

Remediation Suggestions: If the functionality is not essential, it is recommended to remove it, or define a whitelist that users can specify, or filter out internal addresses

image image

Redpeppersir avatar Nov 03 '24 10:11 Redpeppersir