Dismissed
(no matching packages found)
Activity log
- Created & dismissed (no matching packages found) suggestion
OPeNDAP Hyrax SSRF and Credential Disclosure via Unvalidated Redirects
OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.
References
Affected products
hyrax-docker
- ==1.18.0