~ / cve / CVE-2023-XXXXX

CVE-2023-XXXXX

Deutsche Telekom — SSRF leading to internal service access

Summary

A server-side request forgery in a URL-handling feature let an attacker make the server issue requests to internal resources.

The vulnerability

Describe the vulnerable parameter, the lack of allow-listing, and how internal endpoints or cloud metadata could be reached.

Impact

Access to internal services not meant to be reachable from the outside — rated high.