Get-based SSRF limited to HTTP protocol on https://resizer.line-apps.com/form
Medium
L
LY Corporation
Submitted None
Team Summary
Official summary from LY Corporation
A SSRF in the resizer's /form endpoint allowed for leaking HTTP protocol based information from our internal network. The vulnerability could be used to scan ports and get service banners (like SSH versions etc), but it was also possible to leak images available on the internal network. If an attacker knew the URL of images available on the internal network, it was possible to extract potentially sensitive and classified data.
Actions:
Reported by
ledz1996
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Server-Side Request Forgery (SSRF)