Merge commit from fork
* fix: prevent SSRF via redirect in CIMD metadata fetch * fix: prevent SSRF via redirect in CIMD metadata fetch * fix: add redirect target listener to SSRF redirect test
This commit is contained in:
@@ -0,0 +1,5 @@
|
||||
---
|
||||
'@backstage/plugin-auth-backend': patch
|
||||
---
|
||||
|
||||
Fixed a security vulnerability where the CIMD metadata fetch could follow HTTP redirects to internal hosts, bypassing SSRF protections.
|
||||
Reference in New Issue
Block a user