CVE-2022-23206: Server-Side Request Forgery (SSRF)
(updated )
In Apache Traffic Control Traffic Ops, an unprivileged user who can reach Traffic Ops over HTTPS can send a specially-crafted POST request to /user/login/oauth
to scan a port of a server that Traffic Ops can reach.
References
Detect and mitigate CVE-2022-23206 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →