Impact
When running a publicly exposed proxy endpoint without authentication it could allow someone to perform a Server Side Request Forgery (SSRF) attack. Logged in users could do the same on private instances.
Patches
Fixed in #10884. Released in https://github.com/cBioPortal/cbioportal/releases/tag/v6.0.12
Workarounds
Might be able to disable /proxy endpoint entirely via e.g. nginx
References
Impact
When running a publicly exposed proxy endpoint without authentication it could allow someone to perform a Server Side Request Forgery (SSRF) attack. Logged in users could do the same on private instances.
Patches
Fixed in #10884. Released in https://github.com/cBioPortal/cbioportal/releases/tag/v6.0.12
Workarounds
Might be able to disable /proxy endpoint entirely via e.g. nginx
References