NFLX-2018-001
Unauthenticated Server-Side Request Forgery in Hystrix-Dashboard
Patrick Thomas / [email protected]
2018-01-10
Hystrix (specifically hystrix-dashboard)
Hystrix-Dashboard, all versions
Former: https://github.com/Netflix/Hystrix/tree/master/hystrix-dashboard New: https://github.com/Netflix-Skunkworks/hystrix-dashboard
Critical
Hystrix includes an optional hystrix-dashboard component to provide a web dashboard of hystrix status. The dashboard is vulnerable to server-side request forgery in the proxy.stream and monitor.html endpoints. It is recommended that hystrix-dashboard not be used except behind authorization checks.
Hystrix-dashboard is being moved from the main Netflix/Hystrix repository to the Netflix-Skunkworks organization to emphasize that it is an optional and unmaintained component.