SSRF in Rendertron
Vulnerability Description
Rendertron versions prior to 3.0.0 are are susceptible to a Server-Side Request Forgery (SSRF) attack. An attacker can use a specially crafted webpage to force a rendertron headless chrome process to render internal sites it has access to, and display it as a screenshot. Suggested mitigations are to upgrade your rendertron to version 3.0.0, or, if you cannot update, to secure the infrastructure to limit the headless chrome's access to your internal domain.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-8902
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- N Suriya Prakash from Cyber Security and Privacy Foundation Pte Ltd
More from Google LLC
View All →Affected Vendor
Google LLC
View all reports →