Canvas version 2020-07-29 is susceptible to blind server-side request forgery. An attacker can cause Canvas to perform HTTP GET requests to arbitrary domains and thus potentially access sensitive information, modify data, and/or execute unauthorized operations.
View the template here CVE-2020-5775.yaml
References:
https://github.com/ARPSyndicate/cvemon