Impact
CAI Content Credentials contains a Server‑Side Request Forgery vulnerability that allows an attacker to direct the server to fetch arbitrary URLs. This can result in injection of malicious scripts into web pages, providing the attacker with elevated access or control over the victim’s account or session, and the potential for arbitrary code execution in the context of the victim user. The exploitation requires user interaction, such as visiting a maliciously crafted URL or interacting with a compromised web page, and changes the scope of the vulnerability.
Affected Systems
Adobe Content Credentials Command‑Line Tool, Adobe Content Credentials JavaScript SDK, and Adobe Content Credentials Rust SDK are all affected. Version information is not specified, so any current version of these tools could be vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity, while the EPSS score of <1% suggests a low but non‑zero likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote, involving crafted URLs or malicious web pages, and requires a victim to interact with the malicious content.
OpenCVE Enrichment