Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gxvv-45f6-3ch8

Опубликовано: 16 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.5

Описание

A flaw was found in ose-openshift-apiserver. This vulnerability allows internal network enumeration, service discovery, limited information disclosure, and potential denial-of-service (DoS) through Server-Side Request Forgery (SSRF) due to missing IP address and network-range validation when processing user-supplied image references.

A flaw was found in ose-openshift-apiserver. This vulnerability allows internal network enumeration, service discovery, limited information disclosure, and potential denial-of-service (DoS) through Server-Side Request Forgery (SSRF) due to missing IP address and network-range validation when processing user-supplied image references.

EPSS

Процентиль: 14%
0.00046
Низкий

8.5 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 8.5
nvd
около 2 месяцев назад

A flaw was found in ose-openshift-apiserver. This vulnerability allows internal network enumeration, service discovery, limited information disclosure, and potential denial-of-service (DoS) through Server-Side Request Forgery (SSRF) due to missing IP address and network-range validation when processing user-supplied image references.

EPSS

Процентиль: 14%
0.00046
Низкий

8.5 High

CVSS3

Дефекты

CWE-918