Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hhxh-qphc-v423

Опубликовано: 25 сент. 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Nepxion Discovery vulnerable to potential Information Disclosure due to Server-Side Request Forgery

Nepxion Discovery is a solution for Spring Cloud. Discovery is vulnerable to a potential Server-Side Request Forgery (SSRF). RouterResourceImpl uses RestTemplate’s getForEntity to retrieve the contents of a URL containing user-controlled input, potentially resulting in Information Disclosure. There is no patch available for this issue at time of publication. There are no known workarounds.

Пакеты

Наименование

com.nepxion:discovery

maven
Затронутые версииВерсия исправления

<= 6.16.2

Отсутствует

EPSS

Процентиль: 30%
0.00112
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 4.3
nvd
больше 3 лет назад

Nepxion Discovery is a solution for Spring Cloud. Discovery is vulnerable to a potential Server-Side Request Forgery (SSRF). RouterResourceImpl uses RestTemplate’s getForEntity to retrieve the contents of a URL containing user-controlled input, potentially resulting in Information Disclosure. There is no patch available for this issue at time of publication. There are no known workarounds.

EPSS

Процентиль: 30%
0.00112
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-918