The Spinnaker template resolution functionality is vulnerable to Server-Side Request Forgery (SSRF), which allows an attacker to send requests on behalf of Spinnaker potentially leading to sensitive data disclosure.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| com.netflix.spinnaker.orca:orca-core(Maven) | 0 | 8.7.0 | N/A |
CVSS Metrics