OpenMetadata 2.0.2 及之前版本在 URLValidator.validateURL 函数中存在服务端请求伪造(SSRF)漏洞。该函数未能正确解析 DNS 主机名并验证内部地址。拥有创建或更新 EventSubscription 权限的用户,可将 Webhook 目标地址设置为内部主机,从而使服务器向私有网络和云元数据端点发送请求,并返回可用于盲 SSRF 探测的 HTTP 状态码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| open-metadata | OpenMetadata | 0 ~ 2.0.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet