prefect is vulnerable to Server-side Request Forgery (SSRF)
80
High Risk
Affected versions of the package are vulnerable to Server-side Request Forgery (SSRF). If a user self-hosts a Prefect API exposed to external users, a malicious user can configure a notification URL that points to an internal API, such as an internal cloud provider API. This could lead to unauthorized access and exposure of sensitive information.
You are affected if you are using a version that falls within the vulnerable range.
prefect is vulnerable to Server-side Request Forgery (SSRF) in versions 2.8.0 - 2.20.10 and 3.0.0 - 3.0.1.
Upgrade the prefect library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant