Impact
OpenCVE allows a logged‑in user with permission to configure notification channels to supply arbitrary HTTP or HTTPS destinations for Webhook and Slack deliveries. The platform will then make outbound requests to those URLs, potentially accessing internal services, localhost interfaces, link‑local addresses, or cloud metadata endpoints, and the response can be read by the attacker. This creates a vulnerability that can lead to confidentiality loss of internal information and possible enumeration of hidden resources.
Affected Systems
All OpenCVE instances running a version earlier than 3.0.0 are vulnerable. The flaw exists in the notification testing component that processes user‑supplied webhook and Slack URLs.
Risk and Exploitability
The CVSS score is 6.5, indicating a moderate severity. The EPSS score is < 1%, and the flaw is not yet listed in the CISA KEV catalog. Exploitation requires an authenticated user with permission to modify notification channels; the attacker can craft malicious URLs to cause the server to perform requests against any host reachable from the OpenCVE server, including internal and cloud metadata services. The impact is limited to data disclosure through outbound HTTP traffic, but the ability to reach internal networks elevates risk for organizations with sensitive internal resources.
OpenCVE Enrichment
Github GHSA