OpenZiti Ziti Console Server-Side Request Forgery Vulnerability
Vulnerability
A server-side request forgery (SSRF) vulnerability has been identified in OpenZiti Ziti Console versions prior to 3.7.1. An endpoint on the admin panel can be accessed without authentication, allowing users to send requests to an OpenZiti Controller. This vulnerability could be exploited to access internal or external endpoints, including sensitive cloud metadata in environments like AWS.
Impact
Exploitation of this vulnerability allows unauthorized access to sensitive information, such as cloud instance metadata and credentials, which could lead to a broader system compromise.
Remediation
Users can upgrade to OpenZiti Ziti Console version 3.7.1 or later to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
