Discovered by Edward Prior on behalf of The Missing Link Security
The application was vulnerable to a Server-Side Request Forgery attacks, allowing the backend server to interact with unexpected endpoints, potentially including internal and local services. Leading to attacks in other downstream systems.
Discovered in: 19.0
Fixed In: Won’t fix.