
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-9298 is a Server-Side Request Forgery (SSRF) vulnerability discovered in Spinnaker's template resolution functionality. The vulnerability was identified by Venkat from armory.io and disclosed on May 29, 2020. This vulnerability affects Spinnaker's Orca component versions prior to v8.7.0 (Netflix Security).
The vulnerability exists in the /pipelineTemplate endpoint of Spinnaker's template resolution functionality, which allows an attacker to send requests on behalf of Spinnaker. The severity of this vulnerability is rated as HIGH with a CVSS v3.1 score of 7.5 (NVD).
The exploitation of this vulnerability could potentially lead to sensitive data disclosure as attackers can make the server perform unauthorized requests on their behalf (NVD).
Users are recommended to update to Orca version 8.7.0 or later to address this vulnerability. The patch is available in the v8.7.0 release (Netflix Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."