vendor:
Ladder
by:
_chebuya
6.1
CVSS
HIGH
Server-side Request Forgery (SSRF)
918
CWE
Product Name: Ladder
Affected Version From: v0.0.1
Affected Version To: v0.0.21
Patch Exists: NO
Related CWE: CVE-2024-27620
CPE: a:everywall:ladder:0.0.21
Platforms Tested: Ubuntu 20.04.6 LTS on AWS EC2
2024
Ladder v0.0.21 – Server-side Request Forgery (SSRF)
Ladder v0.0.21 does not properly restrict destination addresses, enabling an attacker to send GET requests to addresses that are usually inaccessible externally. This allows unauthorized access to private address ranges, local services, and cloud instance metadata APIs. The vulnerability can be exploited to extract sensitive information.
Mitigation:
To mitigate this vulnerability, implement proper input validation and sanitize user-controlled input to prevent SSRF attacks. Restrict access to external resources and avoid direct server-side requests to untrusted sources.