SSRF via WordPress URL-input (interne services bereikbaar) #87
Labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
jesse-a/OpenCRM#87
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Severity: HIGH
normalizeSiteUrl()insrc/lib/wordpress.tsaccepteerde elkhttp(s)://-doel. Een MANAGER kon dus een WP-site-URL alshttp://169.254.169.254/...(cloud metadata-service) ofhttp://localhost:5432invoeren — de server probeerde dan die fetch te doen tijdens de health-check.Fix:
rejectInternalTarget()weigert IP-literals, localhost,.local/.internal/.intraneten IPv6-adressen.Files: src/lib/wordpress.ts
Opgelost in commit
67b2580.