ietf-wg-gnap / gnap-core-protocol

143 stars 26 forks source link

Security Consideration: SSRF attacks #363

Closed jricher closed 2 years ago

jricher commented 2 years ago

If the client instance can cause the AS to fetch a URL, especially if that URL is dynamic, this can be used as a means to make the AS call URLs within its own protected domain and cause errors. Will need to be addressed in new security considerations paragraph.