Vulnerability Description
The Spinnaker template resolution functionality is vulnerable to Server-Side Request Forgery (SSRF), which allows an attacker to send requests on behalf of Spinnaker potentially leading to sensitive data disclosure.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Spinnaker | Orca | < 8.7.0 |
Related Weaknesses (CWE)
References
- https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2020-0PatchThird Party Advisory
- https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2020-0PatchThird Party Advisory
FAQ
What is CVE-2020-9298?
CVE-2020-9298 is a vulnerability with a CVSS score of 7.5 (HIGH). The Spinnaker template resolution functionality is vulnerable to Server-Side Request Forgery (SSRF), which allows an attacker to send requests on behalf of Spinnaker potentially leading to sensitive d...
How severe is CVE-2020-9298?
CVE-2020-9298 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-9298?
Check the references section above for vendor advisories and patch information. Affected products include: Spinnaker Orca.