Impact
The vulnerability allows an authenticated administrator with admin:access permission to store a remote instance address that can point to internal, loopback, link‑local, or cloud metadata services. During synchronization the server dereferences the address using requests.get() with automatic redirect handling and no network‑boundary checks, permitting the application to make requests to otherwise unreachable internal endpoints. Successful exploitation enables the attacker to probe or interact with services accessible only from the Vulnerability‑Lookup server, potentially exposing sensitive data or compromising system integrity. The actual confidentiality, integrity, or availability impact depends on which internal services are reachable.
Affected Systems
Vulnerability‑Lookup is the only product referenced. No specific affected versions are listed, so all currently deployed instances that have not applied the patch are potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity, and the exploitation probability is not quantified by EPSS. The vulnerability is not present in the CISA KEV catalog. Exploitation requires administrative credentials with admin:access permission; attackers can also leverage publicly accessible URLs that redirect to internal destinations because redirects were followed without revalidation. The primary attack vector is via the remote‑instance synchronization configuration endpoint.
OpenCVE Enrichment