QID 730506
Date Published: 2022-06-06
QID 730506: Apache Shindig Server Side Request Forgery (SSRF) Vulnerability
Apache Shindig is an OpenSocial container and helps you to start hosting OpenSocial apps quickly by providing the code to render gadgets, proxy requests, and handle REST and RPC requests.
Affected version(s):
Apache Shindig 2.5.1 and earlier
QID Detection Logic (Unauthenticated):
The QID checks for SSRF via Proof of Concept (PoC) code.
Successful exploitation of this vulnerability could lead to a security breach or could affect confidentiality, integrity, and availability.
Solution
No patch available yet.
refer to Apache Shindig Official Site for updates.
Vendor References
- WSO2-2019-0598 -
docs.wso2.com/display/Security/Security%2BAdvisory%2BWSO2-2019-0598
CVEs related to QID 730506
Software Advisories
| Advisory ID | Software | Component | Link |
|---|