PT-2022-16006 · Nepxion · Nepxion Discovery

Jorge Rosillo

+1

·

Published

2022-09-24

·

Updated

2022-09-28

·

CVE-2022-23464

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nepxion Discovery (affected versions not specified)
Description The issue is related to a potential Server-Side Request Forgery (SSRF) in Nepxion Discovery, a solution for Spring Cloud. Specifically, the RouterResourceImpl uses RestTemplate's getForEntity to retrieve the contents of a URL containing user-controlled input, potentially resulting in Information Disclosure. There are no known workarounds or patches available for this issue at the time of publication.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Weakness Enumeration

Related Identifiers

CVE-2022-23464
GHSA-HHXH-QPHC-V423

Affected Products

Nepxion Discovery