Impact
OpenCTI’s synchronizerFetch GraphQL query allowed any authenticated user with the INGESTION role to fetch remote streams from arbitrary HTTP or HTTPS URLs without validating the destination. The lack of an ingestion deny list and failure to reject private or loopback addresses introduced a server‑side request forgery flaw described by CWE‑918. This flaw can lead to internal network scans, disclose open ports, and expose sensitive internal services or cloud metadata. The data from the upstream endpoints can be accessed by the OpenCTI platform or downstream systems.
Affected Systems
The vulnerability affects the OpenCTI platform (7.260701.0). Any deployment using or earlier than that release is susceptible, regardless of the operating system or hosting environment.
Risk and Exploitability
The vulnerability has a CVSS score of 7.7 and an EPSS of less than 1%, indicating a high severity but a low probability of exploitation in the wild. It is not listed in the CISA KEV catalog. The attack path requires an authenticated account with INGESTION capability and involves sending a malicious GraphQL query that instructs the server to retrieve a remote stream from a crafted internal URL. Because the server performs no destination validation, the attacker can probe internal services, determine port states, and potentially exfiltrate data. Preventing exposure thus hinges on applying the vendor fix or mitigating the allowed capabilities.
OpenCVE Enrichment