漏洞描述
FlyteConsole is the web user interface for the Flyte platform. FlyteConsole prior to version 0.52.0 is vulnerable to server-side request forgery when FlyteConsole is open to the general internet. An attacker can exploit any user of a vulnerable instance to access the internal metadata server or other unauthenticated URLs. Passing of headers to an unauthorized actor may occur.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
github.comhttps://github.com/flyteorg/flyteconsole/security/advisories/GHSA-www6-hf2v-v9m9↗github.comhttps://github.com/flyteorg/flyteconsole/pull/389↗hackerone.comhttps://hackerone.com/reports/1540906↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2022-24856↗github.comhttps://github.com/flyteorg/flyteconsole/commit/05b88ed2d2ecdb5d8a8404efea25414e57189709↗