FlyteConsole是Flyte的控制台组件。 FlyteConsole 0.52.0 之前版本存在代码问题漏洞,该漏洞源于容易受到服务器端请求伪造 (SSRF) 的攻击。攻击者可以利用易受攻击实例的任何用户访问内部元数据服务器或其他未经身份验证的 URL。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| flyteorg | flyteconsole | < 0.52.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | FlyteConsole is the web user interface for the Flyte platform. FlyteConsole prior to version 0.52.0 is vulnerable to server-side request forgery when FlyteConsole is open to the general internet. An attacker can exploit any user of a vulnerable instance to access the internal metadata server or other unauthenticated URLs. Passing of headers to an unauthorized actor may occur. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-24856.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet