In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Server-side Request Forgery (SSRF) vulnerabilities in an interactive lesson.
Start learningUpgrade org.apache.ranger:security-admin-web
to version 2.5.0 or higher.
Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) through the Edit Service Page interface. An attacker can manipulate server requests to access or interact with internal services by sending crafted requests to the interface.
Note:
This is only exploitable if the server is configured to resolve internal network addresses.