Fider before 0.38.0 SSRF via DNS rebinding in webhook validation
5Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 2.1
exploitation probability
—
observed exploitation
nono source reports it
Fider before 0.38.0 contains a server-side request forgery vulnerability due to a time-of-check time-of-use gap in URL validation for webhooks and custom OAuth provider endpoints. Administrators controlling DNS can perform DNS rebinding attacks to make the Fider server send requests to internal services or cloud metadata endpoints.
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Affected products
getfider · fiderReferences
https://github.com/getfider/fiderhttps://github.com/getfider/fider/blob/v0.37.0/app/pkg/validate/general.gohttps://github.com/getfider/fider/blob/v0.37.0/app/services/httpclient/httpclient.gohttps://github.com/getfider/fider/commit/45f5627b9fd15b912fb9092635c863fb4c91dd69https://github.com/getfider/fider/releases/tag/v0.38.0https://github.com/getfider/fider/security/advisories/GHSA-whx4-hxwq-qgjhhttps://www.vulncheck.com/advisories/fider-before-0.38.0-ssrf-via-dns-rebinding-in-webhook-validation