Impact
The vulnerability allows an authenticated user to trigger outbound HTTP requests to any URL via the /settings/test_notification endpoint. By supplying a crafted URL, the attacker can have the server contact internal or external services, exposing internal networks or obtaining sensitive data. The weakness arises from an unsanitized URLs field that is passed directly to Apprise without restricting protocol, hostname, or address ranges, and is categorized as CWE‑918.
Affected Systems
Quenary's Tugtainer application prior to version 1.30.6 is affected. Authenticated users running the self‑hosted container automation tool may be able to abuse the test_notification endpoint if they have not upgraded to the patched v1.30.6 release. The issue applies to all installations of the affected version on any supported platform.
Risk and Exploitability
The CVSS score of 9.1 signals a high‑severity vulnerability. Although EPSS data is unavailable and the issue is not listed in CISA KEV, the required authentication is typically available to legitimate users of the service, meaning any compromised account can perform blind SSRF attacks. The attacker can use the endpoint to scan internal networks, access metadata services, or exfiltrate data through outbound requests, thereby compromising confidentiality and potentially integrity of internal resources.
OpenCVE Enrichment