Summary
A server-side request forgery in a URL-handling feature let an attacker make the server issue requests to internal resources.
The vulnerability
Describe the vulnerable parameter, the lack of allow-listing, and how internal endpoints or cloud metadata could be reached.
Impact
Access to internal services not meant to be reachable from the outside — rated high.