CVE-2020-8902
EPSS 0.06%SSRF in Rendertron
發布日:2021/3/1修改日:2023/11/8
描述
Rendertron versions prior to 3.0.0 are are susceptible to a Server-Side Request Forgery (SSRF) attack. An attacker can use a specially crafted webpage to force a rendertron headless chrome process to render internal sites it has access to, and display it as a screenshot. Suggested mitigations are to upgrade your rendertron to version 3.0.0, or, if you cannot update, to secure the infrastructure to limit the headless chrome's access to your internal domain.
受影響套件(1)
- npm/rendertronfrom 0, < 3.0.0