Homestyx hydra

R1:45665dd3b458

Hide "notification.servers" configuration and don't follow redirects from Aphlict

Summary:
See <https://hackerone.com/reports/850114>.

An attacker with administrator privileges can configure "notification.servers" to connect to internal services, either directly or with chosen parameters by selecting an attacker-controlled service and having it issue a "Location" redirect.

Generally, we allow this attack to occur. The same administrator can use an authentication provider or a VCS repository to perform…
Repository: R1 hydra
Commit Date: Apr 15 2020