In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal network resources via the Tenable proxy endpoint. This occurs in apps/backend/src/tenable/tenable.controller.ts.Referenceshttps://github.com/mitre/heimdall2/security/advisories/GHSA-g9vx-2rpf-gpchhttps://github.com/mitre/heimdall2/commit/b6a9cdb4fc01f96aaa1a77cc27d1d449b485937bhttps://github.com/mitre/heimdall2/releases/tag/v2.14.0