S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-24856 Scanner

CVE-2022-24856 scanner - Server-Side-Request-Forgery (SSRF) vulnerability in Flyte platform FlyteConsole

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-24856
7.5
CVSScritical
Exploitable remotely over the internet · no authentication required.

FlyteConsole is the web user interface for the Flyte platform. FlyteConsole prior to version 0.52.0 is vulnerable to server-side request forgery (SSRF) when FlyteConsole is open to the general internet. An attacker can exploit any user of a vulnerable instance to access the internal metadata server or other unauthenticated URLs. Passing of headers to an unauthorized actor may occur. The patch for this issue deletes the entire `cors_proxy`, as this is not required for console anymore. A patch is available in FlyteConsole version 0.52.0. Disable FlyteConsole availability on the internet as a workaround.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
flyteconsoleby flyteorg
< 0.52.0
Updated Aug 22, 2026View on NVD →
Detail

FlyteConsole is the web user interface for the Flyte platform. This platform provides a range of tools to help developers and data scientists build, execute, and manage data processing workflows. FlyteConsole is the primary interface for interacting with these workflows, allowing users to define new workflows, monitor existing ones, and analyze their results.

One of the main security vulnerabilities that has recently been detected in FlyteConsole is known as CVE-2022-24856. This vulnerability is a form of server-side request forgery (SSRF) that allows attackers to access internal metadata servers or other unauthenticated URLs. Specifically, if a vulnerable instance of FlyteConsole is open to the internet, attackers could potentially exploit any user of the platform, regardless of their individual access levels or permissions.

The consequences of a successful exploitation of this vulnerability could be significant, and could result in unauthorized access to sensitive or mission-critical data or resources. Attackers could potentially use this access to steal data, disrupt workflows, or even compromise entire systems. Given the potentially serious nature of this vulnerability, it is essential that organizations using FlyteConsole take immediate steps to protect themselves.

Ultimately, the best way to ensure the security of your digital assets is to adopt a comprehensive security strategy that encompasses all aspects of your organization's infrastructure. By leveraging the pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets, and take proactive steps to mitigate these risks. With the right security posture, it is possible to protect against even the most sophisticated threats, and ensure the ongoing integrity and availability of your organization's data processing workflows.

 

REFERENCES

Solution Advice

To protect against this vulnerability, there are a number of best practices that organizations should consider implementing, including:

  • Upgrading to the latest version of FlyteConsole (version 0.52.0 or later), which includes a patch for the SSRF vulnerability.
  • Disabling FlyteConsole availability on the internet, to prevent attackers from accessing the platform via the general internet.
  • Monitoring FlyteConsole usage closely, to identify any unusual activity or patterns that may indicate an attempted attack.
  • Implementing additional security controls such as firewalls, intrusion detection systems, and access controls, to reduce the risk of an attack succeeding.
  • Conducting regular security assessments and penetration testing to identify any other vulnerabilities that may exist in the platform.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.