Impact
A blind Server‑Side Request Forgery (SSRF) flaw exists in DataHub version 1.5.0.1, allowing an attacker who can trigger the image‑fetching routine to supply a crafted URL. When DataHub retrieves the image, it executes arbitrary code supplied by the attacker, yet the response or any error information is not returned to the requester, making detection difficult. The flaw enables remote code execution on the server that hosts DataHub, compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
DataHub v.1.5.0.1 is affected. No additional vendor or product information is provided in the available data.
Risk and Exploitability
The vulnerability can be exploited from any remote system that can send requests to the vulnerable DataHub instance. No CVSS score or EPSS information is available. The flaw is listed as not in the CISA KEV catalog. Because the flaw allows remote code execution and lacks response feedback, the risk to exposed servers is high; however, exact likelihood cannot be quantified without EPSS or CVSS data. The likely attack vector is a remote attacker crafting a URL to trigger the image fetch endpoint from a client.
OpenCVE Enrichment