Impact
Zilliz Attu before version 3.0.0 features a Playground that can forward arbitrary HTTP and HTTPS requests to any public URL without requiring authentication. This absence of access control allows an attacker who can reach the Playground interface to send requests to external sites, potentially enabling data exfiltration or malicious traffic redirection. The vulnerability is a missing authentication weakness (CWE-306) and does not provide direct code execution but can facilitate reconnaissance and proxy-based attacks.
Affected Systems
The issue affects the Zilliz Attu product for all releases earlier than 3.0.0. No specific sub‑versions are listed, so any deployment of Attu below 3.0.0 is susceptible.
Risk and Exploitability
The CVSS score of 5.8 indicates moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation at present. However, because the Playground requires no authentication, an attacker with network access to the Attu instance can abuse the proxy functionality. The exploitation is straightforward via the web interface, making it relatively easy to abuse if the service is exposed.
OpenCVE Enrichment