Uploaded image for project: 'SonarQube'
  1. SonarQube
  2. SONAR-14585

Fix TOC-TOU race conditon in Webhook

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: 8.9
    • Component/s: None
    • Labels:
      None
    • Edition:
      Community

      Description

      Webhooks are exposed to a TOCTOU (Time Of Check, Time Of Use) race condition, possibly leading to Server-Side Request Forgery (SSRF).

        Attachments

          Activity

            People

            Assignee:
            pierre.guillot Pierre Guillot
            Reporter:
            wouter.admiraal Wouter Admiraal
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Dates

              Due:
              Created:
              Updated:
              Resolved: