CVE-2020-9298: SSRF
The Spinnaker template resolution functionality is vulnerable to Server-Side Request Forgery (SSRF), which allows an attacker to send requests on behalf of Spinnaker potentially leading to sensitive data disclosure.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-9298?
CVE-2020-9298 is a vulnerability in the Spinnaker template resolution functionality that allows Server-Side Request Forgery (SSRF) attacks.
How does CVE-2020-9298 work?
CVE-2020-9298 works by allowing an attacker to send requests on behalf of Spinnaker, which can potentially lead to sensitive data disclosure.
What is the severity of CVE-2020-9298?
The severity of CVE-2020-9298 is high (CVSS score of 7.5).
How can I fix CVE-2020-9298?
To fix CVE-2020-9298, you should update Spinnaker Orca to a version higher than 8.7.0.
Where can I find more information about CVE-2020-9298?
You can find more information about CVE-2020-9298 at the following link: [GitHub - Netflix Security Bulletins - CVE-2020-9298](https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2020-003.md)