Skip to content

Conversation

@CallMeMhz
Copy link
Contributor

The previous fix for issue #4413 (commit #4421) still has some flaws. An attacker could potentially exploit a crafted redirection address to redirect to the internal network, thereby leveraging the GetLinkMetadata API to probe internal network information.

@CallMeMhz CallMeMhz requested a review from boojack as a code owner February 21, 2025 06:01
@CallMeMhz CallMeMhz marked this pull request as draft February 21, 2025 07:13
@CallMeMhz CallMeMhz force-pushed the ssrf_redirect branch 2 times, most recently from 573b2b5 to 537a5c3 Compare February 21, 2025 08:01
@CallMeMhz CallMeMhz marked this pull request as ready for review February 21, 2025 08:03
Copy link
Collaborator

@johnnyjoygh johnnyjoygh left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@johnnyjoygh johnnyjoygh merged commit f17774c into usememos:main Feb 21, 2025
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants