This vulnerability is trending on Twitter; this may indicate a growing threat.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Server-side Request Forgery (SSRF) vulnerabilities in an interactive lesson.
Start learningUpgrade lemur to version 1.9.2 or higher.
lemur is a Certificate management and orchestration service
Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) through the improper handling of user-supplied URLs in the acme_url parameter, lack of access control in the certificate key-fetch process, and automatic activation of SSO-provisioned accounts. An attacker can gain unauthorized access to AWS IAM credentials and persistent access to private keys by exploiting these flaws with a valid SSO-authenticated account and crafting requests to internal metadata services and certificate endpoints. This is only exploitable if the attacker has a valid SSO session accepted by the deployment's identity provider.