漏洞描述
Spring Cloud Netflix 2.2.x prior to 2.2.4, 2.1.x prior to 2.1.6, and older unsupported versions are susceptible to server-side request forgery. Applications can use the Hystrix Dashboard proxy.stream endpoint to make requests to any server reachable by the server hosting the dashboard. An attacker can send a request to other servers and thus potentially access sensitive information, modify data, and/or execute unauthorized operations.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
tanzu.vmware.comhttps://tanzu.vmware.com/security/cve-2020-5412↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2020-5412↗github.comhttps://github.com/ARPSyndicate/kenzer-templates↗github.comhttps://github.com/Elsfa7-110/kenzer-templates↗github.comhttps://github.com/pen4uin/awesome-vulnerability-research↗