CRITICALMaven →
Microcks contains a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download
Microcks contains a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download
Affected packages
- io.github.microcks:microcks— before 1.17.1
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://nvd.nist.gov/vuln/detail/CVE-2023-48910
- https://gist.github.com/b33t1e/2a2dc17cf36cd741b2c99425c892d826
- https://github.com/microcks/microcks
- https://github.com/orgs/microcks/discussions/892
Structured record: https://osv.dev/vulnerability/GHSA-gqj2-324p-vx73
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta