Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fjfv-cm2f-px7c

Опубликовано: 16 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.8
CVSS3: 8.2

Описание

DataGear through 6.0.0 contains a server-side request forgery vulnerability in the /dataSet/preview/Http endpoint that allows unauthenticated attackers to execute arbitrary HTTP requests by supplying a caller-controlled URI. Attackers can issue GET, POST, PUT, PATCH, or DELETE requests to internal endpoints and cloud metadata services, receiving full response bodies without authentication or validation.

DataGear through 6.0.0 contains a server-side request forgery vulnerability in the /dataSet/preview/Http endpoint that allows unauthenticated attackers to execute arbitrary HTTP requests by supplying a caller-controlled URI. Attackers can issue GET, POST, PUT, PATCH, or DELETE requests to internal endpoints and cloud metadata services, receiving full response bodies without authentication or validation.

8.8 High

CVSS4

8.2 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 8.2
nvd
2 дня назад

DataGear through 6.0.0 contains a server-side request forgery vulnerability in the /dataSet/preview/Http endpoint that allows unauthenticated attackers to execute arbitrary HTTP requests by supplying a caller-controlled URI. Attackers can issue GET, POST, PUT, PATCH, or DELETE requests to internal endpoints and cloud metadata services, receiving full response bodies without authentication or validation.

8.8 High

CVSS4

8.2 High

CVSS3

Дефекты

CWE-918