NA

CVE-2024-27620

Published: 06/04/2024 Updated: 08/04/2024

Vulnerability Summary

An issue in Ladder v.0.0.1 thru v.0.0.21 allows a remote malicious user to obtain sensitive information via a crafted request to the API.

Exploits

Ladder versions 001 through 0021 fail to apply sufficient default restrictions on destination addresses, allowing an attacker to make GET requests to addresses that would typically not be accessible from an external context An attacker can access private address ranges, locally listening services, and cloud instance metadata APIs ...