The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade @astrojs/netlify to version 8.2.4 or higher.
@astrojs/netlify is a Deploy your site to Netlify
Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) through a permissive regular expression in remotePatternToRegex() and the image.domains mapping in remoteImagesFromAstroConfig() in packages/integrations/netlify/src/index.ts, which build the Netlify Image CDN allowlist entries without anchoring them, so an allowed origin satisfies the pattern wherever it appears in a candidate URL rather than only at the start. An attacker can direct the Image CDN to fetch an address of their choosing, including internal services and cloud metadata endpoints, by placing an allowed origin in the path or query string of the target URL, as in http://127.0.0.1:6379/?url=https://images.example.com/image.png. This requires the application to have configured image.domains or image.remotePatterns, since the allowlist is what is being matched against, and requests reach the fetch through the public /.netlify/images endpoint.
This vulnerability can be avoided by disabling the Image CDN in the adapter configuration.