Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability has been identified in Webstudio that could allow unauthorized access to sensitive cloud instance metadata and internal services. The issue arises from an unauthenticated server-side request forgery flaw within specific proxy routes when a particular environment variable is not set. This could enable attackers to perform reconnaissance on your infrastructure and potentially access internal systems.
- Unauthenticated flaw in proxy routes.
- Could expose internal cloud infrastructure.
- Confirm relevance and exposure of this technology.
Attack Path
How an attacker could exploit the issue
An attacker can initiate a journey by reaching the application's proxy routes, specifically those handling images, videos, or assets. These routes, when misconfigured with a missing environment variable, become vulnerable. By supplying a specially crafted URL to these endpoints, an attacker can trick the server into making requests on their behalf. This can expose sensitive cloud instance metadata, allow access to internal services, and facilitate reconnaissance of the underlying infrastructure.
- No authentication required.
- Triggers by sending a crafted URL.
- Risk: metadata access, internal service access.
Live Threat
Current exploitation, exposure, and threat context
When the `RESIZE_ORIGIN` environment variable is unset, unauthenticated attackers can exploit a server-side request forgery in the `/cgi/image`, `/cgi/video`, and `/cgi/asset` proxy routes. This allows them to send arbitrary URLs, potentially exposing cloud instance metadata, internal services, and enabling network reconnaissance of the instance's infrastructure.
- Instance metadata and internal services at risk.
- Arbitrary URLs read by proxy endpoints.
- Network reconnaissance and service access.
Operational Fix
Recommended remediation, mitigation, and detection steps
This Server-Side Request Forgery (SSRF) vulnerability impacts systems running Webstudio, potentially exposing cloud instance metadata and internal services. Infrastructure and platform teams, alongside security operations, should prioritize identifying all instances of Webstudio, assessing their exposure to external networks, and confirming business criticality. Once identified and prioritized, coordinate remediation efforts with application owners and the vendor.
- Platform and Infrastructure teams own remediation.
- Verify external reachability and asset criticality.
- Plan coordinated vendor and internal updates.