swiftlang / swift

The Swift Programming Language
https://swift.org
Apache License 2.0
67.49k stars 10.35k forks source link

[SR-8124] SSRF vulnerability #50656

Open swift-ci opened 6 years ago

swift-ci commented 6 years ago
Previous ID SR-8124
Radar https://bugs.swift.org/plugins/servlet/oauth/users/icon-uri?consumerUri=http://google.com
Original Reporter hackerone (JIRA User)
Type Bug
Additional Detail from JIRA | | | |------------------|-----------------| |Votes | 0 | |Component/s | | |Labels | Bug | |Assignee | None | |Priority | Medium | md5: 593676d92ad21ebb001e6848e7c52f36

Issue Description:

Hi ,
This message for your Security Team..
I've found a SSRF Vulnerability in your company website
Fix it as soon as Possible
*************************************
Poc : https://bugs.swift.org/plugins/servlet/oauth/users/icon-uri?consumerUri=http://google.com

Reference : https://www.owasp.org/index.php/Server_Side_Request_Forgery

Mohamed Haron
Security Researcher
Bug Bounty Hunter

belkadan commented 6 years ago

Thank you for the report!