CVE-2023-46124
published 2023-10-25CVE-2023-46124: Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in runtime environments, and the enforcement of…
PriorityP344high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.68%
47.6th percentile
Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in runtime environments, and the enforcement of privacy regulations in code. The Fides web application allows a custom integration to be uploaded as a ZIP file containing configuration and dataset definitions in YAML format. It was discovered that specially crafted YAML dataset and config files allow a malicious user to perform arbitrary requests to internal systems and exfiltrate data outside the environment (also known as a Server-Side Request Forgery). The application does not perform proper validation to block attempts to connect to internal (including localhost) resources. The vulnerability has been patched in Fides version `2.22.1`.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ethyca | fides | < 2.22.1 | 2.22.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Fides Server-Side Request Forgery Vulnerability in Custom Integration Upload
osv·2023-10-24
CVE-2023-46124 [HIGH] Fides Server-Side Request Forgery Vulnerability in Custom Integration Upload
Fides Server-Side Request Forgery Vulnerability in Custom Integration Upload
### Impact
The Fides web application allows a custom integration to be uploaded as a ZIP file containing configuration and dataset definitions in YAML format.
It was discovered that specially crafted YAML dataset and config files allow a malicious user to perform arbitrary requests to internal systems and exfiltrate data outside the environment (also known as a Server-Side Request Forgery). The application does not perform proper validation to block attempts to connect to internal (including localhost) resources.
Exploitation is limited to API clients with the `CONNECTOR_TEMPLATE_REGISTER` authorization scope. In the Fides Admin UI this scope is restricted to highly privileged users, specifically root users an
GHSA
Fides Server-Side Request Forgery Vulnerability in Custom Integration Upload
ghsa·2023-10-24
CVE-2023-46124 [HIGH] CWE-918 Fides Server-Side Request Forgery Vulnerability in Custom Integration Upload
Fides Server-Side Request Forgery Vulnerability in Custom Integration Upload
### Impact
The Fides web application allows a custom integration to be uploaded as a ZIP file containing configuration and dataset definitions in YAML format.
It was discovered that specially crafted YAML dataset and config files allow a malicious user to perform arbitrary requests to internal systems and exfiltrate data outside the environment (also known as a Server-Side Request Forgery). The application does not perform proper validation to block attempts to connect to internal (including localhost) resources.
Exploitation is limited to API clients with the `CONNECTOR_TEMPLATE_REGISTER` authorization scope. In the Fides Admin UI this scope is restricted to highly privileged users, specifically root users an
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/ethyca/fides/commit/cd344d016b1441662a61d0759e7913e8228ed1eehttps://github.com/ethyca/fides/releases/tag/2.22.1https://github.com/ethyca/fides/security/advisories/GHSA-jq3w-9mgf-43m4https://github.com/ethyca/fides/commit/cd344d016b1441662a61d0759e7913e8228ed1eehttps://github.com/ethyca/fides/releases/tag/2.22.1https://github.com/ethyca/fides/security/advisories/GHSA-jq3w-9mgf-43m4
2023-10-25
Published