Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in runtime environments, and the enforcement of privacy regulations in code. The Fides web application allows a custom integration to be uploaded as a ZIP file containing configuration and dataset definitions in YAML format. It was discovered that specially crafted YAML dataset and config files allow a malicious user to perform arbitrary requests to internal systems and exfiltrate data outside the environment (also known as a Server-Side Request Forgery). The application does not perform proper validation to block attempts to connect to internal (including localhost) resources. The vulnerability has been patched in Fides version `2.22.1`.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-2765 Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in runtime environments, and the enforcement of privacy regulations in code. The Fides web application allows a custom integration to be uploaded as a ZIP file containing configuration and dataset definitions in YAML format. It was discovered that specially crafted YAML dataset and config files allow a malicious user to perform arbitrary requests to internal systems and exfiltrate data outside the environment (also known as a Server-Side Request Forgery). The application does not perform proper validation to block attempts to connect to internal (including localhost) resources. The vulnerability has been patched in Fides version `2.22.1`.
Github GHSA Github GHSA GHSA-jq3w-9mgf-43m4 Fides Server-Side Request Forgery Vulnerability in Custom Integration Upload
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-09-11T13:21:00.478Z

Reserved: 2023-10-16T17:51:35.572Z

Link: CVE-2023-46124

cve-icon Vulnrichment

Updated: 2024-08-02T20:37:39.913Z

cve-icon NVD

Status : Modified

Published: 2023-10-25T18:17:36.400

Modified: 2024-11-21T08:27:55.783

Link: CVE-2023-46124

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses