You're viewing a limited, public preview. Log in for full access.
OPeNDAP Hyrax SSRF and Credential Disclosure via Unvalidated Redirects
No AI analysis yet.
OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.
37.6th percentile
This link opens an external site that isn't part of the platform.