Impact
The vulnerability allows an authenticated user to perform a server-side request forgery against the CloudTAK basemap import endpoint (PUT /api/basemap). The implementation accepts an attacker-specified URL and forwards it to the server's fetch call without applying address‑classification or redirect validation. As a result, the server can resolve internal or cloud‑metadata addresses, causing the attacker to receive the full HTTP response—including headers such as name, attribution, and tiles[0]—directly in the API response. This provides read access to internal services and cloud metadata, enabling credential theft or internal service disclosure.
Affected Systems
This flaw exists in CloudTAK deployments from dfpc‑coe prior to version 13.22.1. Users running any version older than the released 13.22.1 build are affected.
Risk and Exploitability
The CVSS score is 5, indicating moderate severity, while the EPSS score is less than 1%, suggesting low current exploitation probability. The flaw is not listed in the CISA KEV catalog. Exploitation requires the attacker to authenticate to the application, submit a malicious URL, and is limited to internal or cloud resources reachable from the application’s network. Once the request is made, the attacker obtains the entire response payload, potentially exposing secrets and internal addresses.
OpenCVE Enrichment
Github GHSA