flyteorg/flyteconsole

flyteorg/flyteconsole

Releases211
Frequency1 week 4 days
Last Release
Stars43
The user interface for Flyte

CVE History

CVEPublishedCVSS v3CVSS v2
9.1 CRITICAL5 MEDIUM

FlyteConsole is the web user interface for the Flyte platform. FlyteConsole prior to version 0.52.0 is vulnerable to server-side request forgery (SSRF) when FlyteConsole is open to the general internet. An attacker can exploit any user of a vulnerable instance to access the internal metadata server or other unauthenticated URLs. Passing of headers to an unauthorized actor may occur. The patch for this issue deletes the entire `cors_proxy`, as this is not required for console anymore. A patch is available in FlyteConsole version 0.52.0. Disable FlyteConsole availability on the internet as a workaround.