Impact
Mooncake version 0.3.13.post1 and earlier contain a missing authentication defect in the Store REST service. The service listens on all interfaces (0.0.0.0) and does not require credentials, permitting any network user to call endpoints such as /api/get, /api/put, /api/remove_all and /api/mount. These endpoints expose cached key-value data, allow arbitrary object injection or deletion, and enable attackers to mount segments defined by the attacker, effectively letting them manipulate the storage state.
Affected Systems
The vulnerability affects kvcache-ai’s Mooncake product for versions up to and including 0.3.13.post1. Users running any of these releases are susceptible to unprotected access to the Store REST API.
Risk and Exploitability
The CVSS score of 9.3 signals a high severity issue with full confidentiality, integrity, and availability impact. The vulnerability is accessible from any host that can reach the 0.0.0.0 address, making it a remote exploit with no authentication or privilege escalation prerequisites. EPSS is not available, but the absence from the KEV catalog does not diminish the risk, especially given the potentially broad impact. Attacker can fully control the storage service, compromising data integrity and application state.
OpenCVE Enrichment