Vulnerability GHSA-87mg-5grr-rhwh
Summary
Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Module
Details
Summary
The Feed Reader front-end module passes RSS feed URLs from its configuration directly to $this->feedIo->read($url) without any scheme validation or private-IP blocklist. A backend user with module-edit permissions can configure an arbitrary URL pointing to internal network services, cloud-provider metadata endpoints, or loopback addresses, causing the server to fetch those resources unconditionally. Confirmed live: the server successfully reaches the internal MySQL database container and its own loopback Apache instance.
Impact
This is a CWE-918 (SSRF) vulnerability. A backend user with module-edit access can:
- Enumerate internal network services -- probe any IP/port on the internal network by observing response times and error messages
- Reach internal APIs -- access unauthenticated services inside the Docker/Kubernetes network (databases, caches, admin panels)
- Steal cloud metadata credentials -- on AWS, fetch
http://169.254.169.254/latest/meta-data/iam/security-credentials/to obtain IAM role credentials (IMDSv1 has no authentication) - Pivot to internal infrastructure -- use the server as a proxy to interact with services not exposed to the public internet
Confirmed in live testing: the server successfully connected to the internal MySQL container (172.19.0.3:3306) and retrieved a full HTTP response from its own loopback interface (127.0.0.1:80).
Related Vulnerabilities
Other vulnerabilities affecting the same packages