Home / os / wince

Ladder 0.0.21 Server-Side Request Forgery

Posted on 09 March 2024

Ladder versions 0.0.1 through 0.0.21 fail to apply sufficient default restrictions on destination addresses, allowing an attacker to make GET requests to addresses that would typically not be accessible from an external context. An attacker can access private address ranges, locally listening services, and cloud instance metadata APIs.

 

TOP