microsoft / msopentech-tools-for-intellij

Plugin for easy and fast development to enable developers of Android Apps to connect to Office 365 services and Azure Mobile Services, and developers of Java middleware to connect to Azure compute services
Apache License 2.0
28 stars 34 forks source link

ssrf #386

Open QiAnXinCodeSafe opened 5 years ago

QiAnXinCodeSafe commented 5 years ago

The attacker can control the name value to ip:port/#, and the patched url is https://ip:port/#.azure-mobile.net, so that the ssrf attack can be performed. 图片 图片