stoatchat
- <= 0.13.4
A server-side request forgery (SSRF) vulnerability has been identified in Stoatchat versions prior to 0.13.5. The vulnerability exists in the January service's /proxy and /embed endpoints, which accept arbitrary URLs from unauthenticated users without proper validation. This lack of filtering allows attackers to enumerate internal services, fingerprint applications, and access instance metadata endpoints in cloud environments by supplying malicious URLs or exploiting redirect chains to reach internal infrastructure.
Exploitation of this vulnerability allows unauthenticated users to probe the internal network of a Stoatchat deployment, potentially accessing sensitive instance metadata in cloud environments that could include IAM credentials.
The vulnerability can be reproduced by sending requests to the /january/proxy or /january/embed endpoints with URLs that point to internal services. The January service will process these requests without authentication or proper validation, allowing access to internal infrastructure.
Users are advised to update Stoatchat to version 0.13.5 or later, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.