GHSA-v4qh-6367-4cx2
HIGHCVE-2020-1925Apache Olingo versions 4.0.0 to 4.7.0 provide the AsyncRequestWrapperImpl class which reads a URL from the Location header, and then sends a GET or DELETE request to this URL. It may allow to implement a SSRF attack. If an attacker tricks a client to connect to a malicious server, the server can make the client call any URL including internal resources which are not directly accessible by the atta
- Affected
- >= 4.0.0, <= 4.7.0
- Fixed in
- 4.7.1
- Weakness
- CWE-918
- Published
- 2020-02-04
- Source
- github