SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-24856

FlyteConsole prior to version 0.52.0 is vulnerable to server-side request forgery (SSRF) when FlyteConsole is open to the general internet.

HIGH 7.5EPSS 10.5%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 10.5%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.

Description

FlyteConsole is the web user interface for the Flyte platform. FlyteConsole prior to version 0.52.0 is vulnerable to server-side request forgery (SSRF) when FlyteConsole is open to the general internet. An attacker can exploit any user of a vulnerable instance to access the internal metadata server or other unauthenticated URLs. Passing of headers to an unauthorized actor may occur. The patch for this issue deletes the entire `cors_proxy`, as this is not required for console anymore. A patch is available in FlyteConsole version 0.52.0. Disable FlyteConsole availability on the internet as a workaround.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
10.48% probability · 95th percentile
CISA KEV
Not listed
Weakness
CWE-918
Affected
flyte/flyte console
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.