Severity: moderate

    Server-Side Request Forgery

    rendertron

    Overview

    rendertron prior to version 3.0.0 is susceptible to a Server-Side Request Forgery (SSRF) attack. An attacker can use a specially crafted webpage to force a rendertron headless chrome process to render internal sites it has access to, and display it as a screenshot.

    Remediation

    Upgrade to version 3.0.0 or later.

    Resources

    Have content suggestions? Visit npmjs.com/support.

    Advisory timeline

    1. published

      Advisory Published
      Mar 1st, 2021
    2. reported

      Reported by Anonymous
      Mar 1st, 2021