GHSA-7c9q-38r9-q62mMediumCVSS 6.5
OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass...
🔗 CVE IDs covered (1)
📋 Description
OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.