The ECT Provider component in OutSystems Platform Server 10 before 10.0.1104.0 and 11 before 11.9.0 (and LifeTime management console before 11.7.0) allows SSRF for arbitrary outbound HTTP requests.
| Software | From | Fixed in |
|---|---|---|
| outsystems / lifetime_management_console | 11 | 11.7.0 |
| outsystems / platform_server | 11 | 11.9.0 |
| outsystems / outsystems | 10 | 10.0.1104.0 |