Skip to content

Instantly share code, notes, and snippets.

@Fadavvi
Last active September 22, 2022 10:56
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save Fadavvi/9fffcfa4aaa9e25b77cfe7b3044b2857 to your computer and use it in GitHub Desktop.
Save Fadavvi/9fffcfa4aaa9e25b77cfe7b3044b2857 to your computer and use it in GitHub Desktop.
CVE-2022-38580
Name of an affected Product: Skipper [AKA Zalando Skipper] <= v0.13.236
Description: Zalando Skipper (<= v0.13.236) is vulnerable to Server-Side Request Forgery
Affected version(s): <= v0.13.236
Fixed Version: v0.13.237
CVE ID: CVE-2022-38580
Vulnerability Type: SSRF [Server-Side Request Forgery]
Root Cause: Custome Header [X-Skipper-Proxy]
References: https://github.com/zalando/skipper/releases/tag/v0.13.237
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment