Skip to content

fix: allowlist configurable intel base URLs to prevent SSRF (APPENG-5712 / T-010) - #348

Open
heatherzh01 wants to merge 1 commit into
mainfrom
threat-T-010-fix
Open

fix: allowlist configurable intel base URLs to prevent SSRF (APPENG-5712 / T-010)#348
heatherzh01 wants to merge 1 commit into
mainfrom
threat-T-010-fix

Conversation

@heatherzh01

Copy link
Copy Markdown

Replace prepare_url() structure-only checks with a hostname allowlist on
NVD/GHSA/RHSA/SerpAPI and other intel base URLs. Permit nginx-cache short
names and in-cluster FQDNs used by kustomize/Tekton; reject metadata, the
k8s API, and arbitrary internal services. Validate at client init and at
workflow startup.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant