SSRF vulnerability can be exploited when a hijacked aggregated api server such as metrics-server returns 30X