QID 983835

QID 983835: Java (maven) Security Update for com.netflix.spinnaker.orca:orca-core (GHSA-4fcw-pq4r-f4q7)

The Spinnaker template resolution functionality is vulnerable to Server-Side Request Forgery (SSRF), which allows an attacker to send requests on behalf of Spinnaker potentially leading to sensitive data disclosure.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-4fcw-pq4r-f4q7 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 983835

    Software Advisories
    Advisory ID Software Component Link
    GHSA-4fcw-pq4r-f4q7 com.netflix.spinnaker.orca:orca-core URL Logo github.com/advisories/GHSA-4fcw-pq4r-f4q7