QID 150430
Date Published: 2022-04-22
QID 150430: Adobe Experience Manager: SSRF via Opensocial
SSRF via Opensocial (shindig) proxy. See - https://speakerdeck.com/fransrosen/a-story-of-the-passive-aggressive-sysadmin-of-aem?slide=41 SSRF via Opensocial (shindig) makeRequest. Yon can specify parameters httpMethod, postData, headers, contentType for makeRequest.
A SSRF vulnerability in an application can allow an attacker to communicate or interact with an otherwise unreachable or unauthorized service. A successful attack may cause the application to disclose sensitive information to the attacker or to induce the application to retrieve and process malicious content.
Solution
Follow security guidelines provided by Adobe Experience Manager https://experienceleague.adobe.com/docs/experience-manager-64/administering/security/security.html?lang=en. Make sure security configuration is applied correctly.
Vendor References
CVEs related to QID 150430
Software Advisories
| Advisory ID | Software | Component | Link |
|---|