VU#305509: OPeNDAP Hyrax is vulnerable to SSRF and Credential Disclosure
A vulnerability has been discovered in the OPeNDAP Hyrax software solution. This vulnerability allows a remote attacker to cause the application to communicate with unauthorized remote systems. It is classified as a Server Side Request Forgery (SSRF) and credential disclosure issue. The vulnerability stems from unvalidated HTTP redirects that bypass normal security checks. Hyrax fails to re-validate redirect destinations against its AllowedHosts list. Consequently, it can be tricked into connecting to untrusted or internal networks. Additionally, user authentication tokens, such as Echo-Token, may be leaked to attacker-controlled endpoints. Successful exploitation can grant attackers access to internal services not meant for public access. If a user is authenticated, their credentials could be compromised. Administrators are advised to review allowed host configurations and limit gateway endpoint exposure. A patch is expected soon from OPeNDAP, likely in version 1.18.0 or later.