Impact
Ocelot up to version 24.1.0 has a security control bypass that lets clients with blocked IPs send WebSocket upgrade requests, causing the pipeline to the SecurityMiddleware and proxy traffic to downstream services. This enables attackers to reach services that should be denied, potentially exposing sensitive data or allowing further compromise.
Affected Systems
The affected product is ThreeMammals Ocelot, specifically versions up to and including 24.1.0; the issue resides in the MapWhen configuration branch that handles WebSocket upgrades.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical severity. EPSS data is unavailable, so the exact likelihood of exploitation cannot be quantified at this time. The vulnerability is not listed in the CISA KEV catalog, but the attack vector is remote, relying on a client to initiate a WebSocket upgrade from a blocked IP address, bypassing the IP allow/block list before any access control is applied.
OpenCVE Enrichment