Loading HuntDB...

Blind SSRF on image proxy camo.stream.highwebmedia.com

Medium
C
Chaturbate
Submitted None

Team Summary

Official summary from Chaturbate

The hacker discovered that our secure image proxy camo.stream.highwebmedia.com could be used to access http(s) endpoints on internal ips. The application was patched to not allow access to internal ips. In this case these servers are in a separate cluster with no access to other services so possible exploitation was limited.

Reported by hackaccinocraft

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Server-Side Request Forgery (SSRF)