Impact
DataHub version 1.5.0.1 contains a blind Server‑Side Request Forgery flaw that allows an attacker to supply a crafted URL for the image‑fetching routine. When the server retrieves the image, the attacker can embed code that is executed during the request, providing remote code execution while the server returns no content or error to the requester, making detection difficult. This vulnerability falls under CWE‑918 and therefore permits arbitrary code execution on the DataHub host, endangering confidentiality, integrity, and availability.
Affected Systems
DataHub v.1.5.0.1 is affected. No other vendors or product versions are listed in the available data.
Risk and Exploitability
The flaw carries a CVSS score of 9.8, which is critical, and an EPSS score of < 1%, indicating a low current exploitation probability. It is not listed in the CISA KEV catalog. The attack vector is a remote attacker who can trigger the image retrieval path, typically by sending a crafted request that causes DataHub to fetch an image from an externally controlled URL. Successful exploitation results in arbitrary code execution on the server hosting DataHub; the lack of returned error or content messages can allow the attacker to remain undetected.
OpenCVE Enrichment