macOS xterm-256color zsh 2 views

Netflix Lemur 1.9.0 — any SSO-authenticated user creates an ACME authority with attacker-controlled acme_url → outbound HTTP reaches AWS IMDS → STS credentials exfiltrated. Same attacker exploits creator-equality IDOR at certificates/views.py:734 to extract private keys post-ownership-transfer. CWE-918 + CWE-639 + CWE-285. Authorized HackerOne lab.