Skip to content

Instantly share code, notes, and snippets.

View Fadavvi's full-sized avatar
⚒️
Busy on progress

Milad Fadavvi Fadavvi

⚒️
Busy on progress
View GitHub Profile
@Fadavvi
Fadavvi / CVE-2022-38580
Last active September 22, 2022 10:56
CVE-2022-38580
Name of an affected Product: Skipper [AKA Zalando Skipper] <= v0.13.236
Description: Zalando Skipper (<= v0.13.236) is vulnerable to Server-Side Request Forgery
Affected version(s): <= v0.13.236
Fixed Version: v0.13.237
CVE ID: CVE-2022-38580
Vulnerability Type: SSRF [Server-Side Request Forgery]
Root Cause: Custome Header [X-Skipper-Proxy]
References: https://github.com/zalando/skipper/releases/tag/v0.13.237