security1 distinct publisher
Pillar chains a 9.1 SSRF to self-minted session IDs in Grafana's MCP server
Grafana's MCP server checked that a session ID looked like one instead of checking that it had issued it. Paired with a CVSS 9.1 SSRF in the same server, that gave unauthenticated callers a proxy inside the network.
Publishers:scworld.com
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+12
- Incentives70