Exposed proxy allows to access internal reddit domains
High
Vulnerability Details
## Summary:
Proxy at https://52.90.28.77:30920 allows to access internal domains
## Steps To Reproduce:
To reproduce, simply use this curl command
```
curl --insecure https://52.90.28.77:30920/reddit --header "Host: █████████"
```
## Supporting Material
snoo.dev is obviously an internal domains used by employees:
https://search.censys.io/search?resource=certificates&q=snoo.dev
It is also references in the GitHub a few times:
https://github.com/search?q=org%3Areddit%20snoo.dev&type=code
## Impact
Attacker can access internal domains
Actions
View on HackerOneReport Stats
- Report ID: 2967634
- State: Closed
- Substate: resolved
- Upvotes: 5