Server-Side Request Forgeryrendertron
rendertron prior to version 3.0.0 is susceptible to a Server-Side Request Forgery (SSRF) attack. An attacker can use a specially crafted webpage to force a rendertron headless chrome process to render internal sites it has access to, and display it as a screenshot.
Upgrade to version 3.0.0 or later.
publishedAdvisory PublishedMar 1st, 2021
reportedReported by AnonymousMar 1st, 2021