vendor:
Skipper
by:
Hosein Vita & Milad Fadavvi
9.8
CVSS
CRITICAL
Server Side Request Forgery (SSRF)
918
CWE
Product Name: Skipper
Affected Version From: < v0.13.237
Affected Version To: v0.13.236
Patch Exists: YES
Related CWE: CVE-2022-38580
CPE: a:zalando:skipper
Platforms Tested: Linux
2022
X-Skipper-Proxy v0.13.237 – Server Side Request Forgery (SSRF)
Skipper prior to version v0.13.236 is vulnerable to server-side request forgery (SSRF). An attacker can exploit a vulnerable version of proxy to access the internal metadata server or other unauthenticated URLs by adding an specific header (X-Skipper-Proxy) to the http request.
Mitigation:
Upgrade to version v0.13.236 or later