Summary
A Full Read Server-Side Request Forgery (SSRF) vulnerability has been identified in the "Add Link" feature. This flaw allows an authenticated attacker with general user privileges to send arbitrary GET requests to the internal network and exfiltrate the full response body. By exploiting this vulnerability, an attacker can steal sensitive data from internal services and cloud metadata endpoints.
Impact
- Full Read SSRF: Ability to read the full HTTP/HTTPS response body from services within the internal network.
- Exfiltration of Sensitive Data:
- Cloud Metadata: Under certain conditions (e.g., environments not requiring custom headers), instance credentials and IAM roles can be stolen from metadata endpoints.
- Internal Network Resources: Data theft from internal APIs or unauthenticated internal services (e.g., object storage).
- Internal Reconnaissance: Identifying the status of hosts and ports within the isolated internal network.
Summary
A Full Read Server-Side Request Forgery (SSRF) vulnerability has been identified in the "Add Link" feature. This flaw allows an authenticated attacker with general user privileges to send arbitrary GET requests to the internal network and exfiltrate the full response body. By exploiting this vulnerability, an attacker can steal sensitive data from internal services and cloud metadata endpoints.
Impact