GoogleChrome / rendertron

A Headless Chrome rendering solution

Home Page:https://render-tron.appspot.com/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

SSRF on rendertron

erik-451 opened this issue · comments

commented

There is a SSRF that allow an attacker to see private services of the network, and can leak confidential data.
image

That is a problem in the affected applications. If they are vulnerable through Rendertron, they will be vulnerable without Rendertron, too.