Soft Serve is a self-hostable Git server for the command line. Versions prior to 0.11.1 have a SSRF vulnerability where webhook URLs are not validated, allowing repository administrators to create webhooks targeting internal services, private networks, and cloud metadata endpoints. Version 0.11.1 fixes the vulnerability.
The vulnerability results from lack of URL validation when creating webhooks in Soft Serve (CWE-918 — Server-Side Request Forgery). A repository administrator can configure a webhook pointing to any address, including resources accessible only on the server side. The server then executes an HTTP request to the specified address on its own behalf, allowing the attacker to probe internal infrastructure or retrieve sensitive data, such as tokens from cloud metadata endpoints (e.g., AWS IMDSv1).
An attacker with repository administrator privileges can gain access to internal network services not publicly accessible and read sensitive data, including credentials from cloud environment metadata endpoints. Limited modification of the state of internal services accepting HTTP requests is also possible.
Soft Serve should be updated to version 0.11.1, which introduces webhook URL validation and eliminates the vulnerability. Patch available in the producer's GitHub repository (commit bb73b9a0eea0d902da4811420535842a4f9aae3b) and in the official release v0.11.1.
Soft Serve (Charm) — all versions prior to 0.11.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:LCharm Soft Serve
APPCharm< 0.11.1
Related vulnerabilities
SSRF w Soft Serve — dostęp do wewnętrznych usług przez LFS endpoint
Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.6, an...
Soft Serve is a self-hostable Git server for the command line. Versions 0.11.2 and below have a critical authe...
Soft Serve is a self-hostable Git server for the command line. Prior to version 0.6.2, a security vulnerabilit...
Soft Serve to samodzielnie hostowany serwer Git dla linii poleceń. Przed wersją 0.11.2 błąd autoryzacji w endp...