NFLX-2020-003
Authenticated Server-Side Request Forgery in Spinnaker
Venkat from armory.io
Dan Kohlbrenner / [email protected]
05/29/2020
Spinnaker (specifically Orca)
orca < v8.7.0
https://github.com/spinnaker/orca
Critical
Venkat discovered that the Spinnaker template resolution functionality is vulnerable to the Server-Side Request Forgery on the /pipelineTemplate endpoint. It is recommended that users update to the v8.7.0 release.
orca < v8.7.0 https://github.com/spinnaker/orca/releases/tag/v8.7.0