Impact
The vulnerability is a server‑side request forgery in the URLSecurityValidator of Compliance‑Trestle that allows bypassing the allowlist by using IPv4‑mapped IPv6 literals such as [::ffff:169.254.169.254] and the unspecified IPv4 address 0.0.0.0. This bypass permits the tool to fetch resources from loopback, link‑local, cloud instance‑metadata, and other internal network endpoints that were intended to be blocked, potentially exposing sensitive internal services and data.
Affected Systems
The affected product is oscal‑compass compliance‑trestle (Trestle) versions prior to 3.12.4 and versions 4.0.0 through 4.0.3. The fix is available in 3.12.4 and 4.1.0.
Risk and Exploitability
With a CVSS score of 8.6 the vulnerability is classified as high severity, and although the EPSS score is available but indicates a very low probability (< 1%) it remains a serious risk. The attack requires an attacker to supply or influence an OSCAL artifact that Trestle will fetch; once this is achieved the attacker can cause Trestle to contact cloud metadata services, loopback interfaces, or internal hosts. The vulnerability is not listed in CISA’s KEV catalog, but the potential impact on internal network reconnaissance or data exfiltration warrants immediate attention.
OpenCVE Enrichment
Github GHSA