Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mcxg-3vgg-9774

Опубликовано: 07 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.1
CVSS3: 5.5

Описание

NocoBase through 2.1.20 contains a server-side request forgery vulnerability in the serverRequest wrapper that allows authenticated administrators to issue arbitrary outbound HTTP requests by supplying malicious URLs to workflow request nodes, custom request action buttons, or the AI plugin. Attackers can target loopback addresses, RFC-1918 private ranges, and cloud instance metadata endpoints to perform internal network port enumeration, host discovery, and retrieval of IAM role credentials from the instance metadata service. v2.1.18 added a warning message for when SERVER_REQUEST_WHITELIST is not configured.

NocoBase through 2.1.20 contains a server-side request forgery vulnerability in the serverRequest wrapper that allows authenticated administrators to issue arbitrary outbound HTTP requests by supplying malicious URLs to workflow request nodes, custom request action buttons, or the AI plugin. Attackers can target loopback addresses, RFC-1918 private ranges, and cloud instance metadata endpoints to perform internal network port enumeration, host discovery, and retrieval of IAM role credentials from the instance metadata service. v2.1.18 added a warning message for when SERVER_REQUEST_WHITELIST is not configured.

EPSS

Процентиль: 26%
0.00337
Низкий

5.1 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 5.5
nvd
около 2 месяцев назад

NocoBase through 2.1.20 contains a server-side request forgery vulnerability in the serverRequest wrapper that allows authenticated administrators to issue arbitrary outbound HTTP requests by supplying malicious URLs to workflow request nodes, custom request action buttons, or the AI plugin. Attackers can target loopback addresses, RFC-1918 private ranges, and cloud instance metadata endpoints to perform internal network port enumeration, host discovery, and retrieval of IAM role credentials from the instance metadata service. v2.1.18 added a warning message for when SERVER_REQUEST_WHITELIST is not configured.

EPSS

Процентиль: 26%
0.00337
Низкий

5.1 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-918