REDHAT-BUG-1790309: SSRF
Apache Olingo versions 4.0.0 to 4.7.0 provide the AsyncRequestWrapperImpl class which reads a URL from the Location header, and then sends a GET or DELETE request to this URL. It may allow to implement a SSRF attack. If an attacker tricks a client to connect to a malicious server, the server can make the client call any URL including internal resources which are not directly accessible by the attacker.
Upstream issue:
https://issues.apache.org/jira/browse/OLINGO-1416
References:
https://mail-archives.apache.org/modmbox/olingo-user/202001.mbox/%3CCAGSZ4d6HwpF2woOrZJgd0SkHytXJaCtAWXa3ZtBn33WG0YFvw%40mail.gmail.com%3E
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1790309?
The severity of REDHAT-BUG-1790309 is considered critical due to the potential for Server-Side Request Forgery (SSRF) attacks.
How do I fix REDHAT-BUG-1790309?
To fix REDHAT-BUG-1790309, upgrade Apache Olingo to a version later than 4.7.0.
Which versions of Apache Olingo are affected by REDHAT-BUG-1790309?
Apache Olingo versions 4.0.0 to 4.7.0 are affected by REDHAT-BUG-1790309.
What is the impact of REDHAT-BUG-1790309?
The impact of REDHAT-BUG-1790309 includes the potential exposure to SSRF attacks, allowing attackers to access internal resources.
Is there a workaround for REDHAT-BUG-1790309?
There is no specific workaround for REDHAT-BUG-1790309; upgrading to a patched version is recommended.