{ "Name": "Sentinel Sentinel-dashboard SSRF", "Description": "

Sentinel is a powerful flow control component issued by Alibaba, which can realize the reliability, flexibility and monitoring of microservices.

The Sentinel control platform Sentinel-dashboard has a pre-authentication SSRF vulnerability. There is no verification in the ip field, and it can be truncated by passing #. Attackers can perform SSRF attacks through this interface.

", "Product": "Sentinel", "Homepage": "https://github.com/alibaba/Sentinel", "DisclosureDate": "2021-11-23", "Author": "1291904552@qq.com", "FofaQuery": "body=\"Sentinel Dashboard\"", "GobyQuery": "body=\"Sentinel Dashboard\"", "Level": "2", "Impact": "

The Sentinel control platform Sentinel-dashboard has a pre-authentication SSRF vulnerability. There is no verification in the ip field, and it can be truncated by passing #. Attackers can perform SSRF attacks through this interface.

", "Recommendation": "

The vendor has released a bug fix, please pay attention to the update in time: https://github.com/alibaba/Sentinel

1. Set access policies and whitelist access through security devices such as firewalls.

2.If not necessary, prohibit public network access to the system.

", "Translation": { "CN": { "Name": "Sentinel Sentinel-dashboard SSRF", "VulType": ["SSRF漏洞"], "Tags": ["SSRF漏洞"], "Description": "

Sentinel是阿里巴巴发行的一个强大的流量控制组件,可实现微服务的可靠性、弹性和监控平台。

Sentinel 管控平台 Sentinel-dashboard 存在认证前 SSRF 漏洞,ip字段无任何验证,通过#就可以截断,攻击者可通过该接口进行 SSRF 攻击。

", "Impact": "

Sentinel 管控平台 Sentinel-dashboard 存在认证前 SSRF 漏洞,ip字段无任何验证,通过#就可以截断,攻击者可通过该接口进行 SSRF 攻击。

", "Product": "Sentinel", "Recommendation": "

⼚商已发布了漏洞修复程序,请及时关注更新:https://github.com/alibaba/Sentinel

1、通过防⽕墙等安全设备设置访问策略,设置⽩名单访问。

2、如⾮必要,禁⽌公⽹访问该系统。

" }, "EN": { "Name": "Sentinel Sentinel-dashboard SSRF", "VulType": ["ssrf"], "Tags": ["ssrf"], "Description": "

Sentinel is a powerful flow control component issued by Alibaba, which can realize the reliability, flexibility and monitoring of microservices.

The Sentinel control platform Sentinel-dashboard has a pre-authentication SSRF vulnerability. There is no verification in the ip field, and it can be truncated by passing #. Attackers can perform SSRF attacks through this interface.

", "Impact": "

The Sentinel control platform Sentinel-dashboard has a pre-authentication SSRF vulnerability. There is no verification in the ip field, and it can be truncated by passing #. Attackers can perform SSRF attacks through this interface.

", "Product": "Sentinel", "Recommendation": "

The vendor has released a bug fix, please pay attention to the update in time: https://github.com/alibaba/Sentinel

1. Set access policies and whitelist access through security devices such as firewalls.

2.If not necessary, prohibit public network access to the system.

" } }, "References": [ "https://github.com/alibaba/Sentinel/issues/2451" ], "HasExp": true, "ExpParams": [ { "name": "ssrf", "type": "input", "value": "xxx.dnslog.cn" } ], "ExpTips": null, "ScanSteps": null, "Tags": [ "ssrf" ], "VulType": [ "ssrf" ], "CVEIDs": [ "" ], "CVSSScore": "7.0", "AttackSurfaces": { "Application": ["Sentinel"], "Support": null, "Service": null, "System": null, "Hardware": null }, "CNNVD": [ "" ], "CNVD": [ "" ] }