Two unauthenticated diagnostic endpoints allow arbitrary backend-initiated network connections to an attacker‑supplied destination. Both endpoints are exposed with permission => 'any', enabling unauthenticated SSRF for internal network scanning and service interaction.
This issue affects OpenSupports: 4.11.0.
| Software | From | Fixed in |
|---|---|---|
| opensupports / opensupports | 4.11.0 | 4.11.0.x |