← Back to browse
·
API
CVE-2022-38580
Severity
CRITICAL
CVSS
9.8
EPSS
0.10867
Risk score
43.0
CISA KEV
No
PoC
No
Published
2022-10-24
Modified
2026-07-09
First seen
2026-08-07
Aliases
EUVD-2022-7084, GHSA-F2RJ-M42R-6JM2
Products
n/a:n/a n/a
Sources
euvd
EUVD-2022-7084
Description
Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).
References
https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-7084
https://pastebin.com/dXxpgPAK
https://gist.github.com/Fadavvi/9fffcfa4aaa9e25b77cfe7b3044b2857#file-cve-2022-38580
http://packetstormsecurity.com/files/171546/X-Skipper-Proxy-0.13.237-Server-Side-Request-Forgery.html