OSV 1.4.0 · github-reviewed · 修改于 2021-02-24 14:59
发布时间
2021-03-02 03:38
GitHub 审查时间
2021-02-24 14:59
NVD 发布时间
2021-02-23 20:15
源文件
advisories/github-reviewed/2021/03/GHSA-xr9h-9m79-x29g/GHSA-xr9h-9m79-x29g.json
Rendertron versions prior to 3.0.0 are are susceptible to a Server-Side Request Forgery (SSRF) attack. An attacker can use a specially crafted webpage to force a rendertron headless chrome process to render internal sites it has access to, and display it as a screenshot. Suggested mitigations are to upgrade your rendertron to version 3.0.0, or, if you cannot update, to secure the infrastructure to limit the headless chrome's access to your internal domain.