Impact
Based on the description, the vulnerability originates from a missing authentication check in the addInterceptors function of DataLinkDC dinky’s OpenAPI configuration, allowing an attacker to send requests to the endpoint without credentials. This flaw can lead to unauthorized access and confidentiality risks for the data served by the API, and may enable further exploitation if privileged operations are exposed.
Affected Systems
The affected product is DataLinkDC dinky. All releases up to and including version 1.2.5 are impacted.
Risk and Exploitability
With a CVSS score of 6.9, the vulnerability is considered moderate. The EPSS score is less than 1%, indicating a low likelihood of exploitation, but it is publicly disclosed and can be leveraged remotely. The exploit does not require local access and uses the missing authentication to gain entry to the OpenAPI interface, which is available over the network.
OpenCVE Enrichment