OpenZiti Ziti Console Server-Side Request Forgery Vulnerability

Vulnerability

A server-side request forgery (SSRF) vulnerability has been identified in OpenZiti Ziti Console versions prior to 3.7.1. An endpoint on the admin panel can be accessed without authentication, allowing users to send requests to an OpenZiti Controller. This vulnerability could be exploited to access internal or external endpoints, including sensitive cloud metadata in environments like AWS.

Impact

Exploitation of this vulnerability allows unauthorized access to sensitive information, such as cloud instance metadata and credentials, which could lead to a broader system compromise.

Remediation

Users can upgrade to OpenZiti Ziti Console version 3.7.1 or later to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.3
exploitability
7.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.