Impact
The vulnerability lies in yaojingang GEOFlow’s DistributionController.isValidHttpEndpoint method, where the supplied endpoint URL is insufficiently validated. An attacker can send a crafted URL that the server will request, resulting in a server-side request forgery. This allows the remote actor to cause the application to connect to any internal or external network resource, potentially exfiltrating data or facilitating further attacks, as described in the official advisory.
Affected Systems
All installations of yaojingang GEOFlow that are running version 2.1.0 or earlier are affected. The vendor has released a fix in version 2.1.1 (commit 67abfd864a15d169a78429f3290c91cb3b93e849) and recommends upgrading to that version to address the issue.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity, while the publicly disclosed nature of the flaw and the lack of an EPSS score mean exploitation is still plausible. The vulnerability is not listed in the CISA KEV catalog, but discussion on public platforms suggests that it may already be in use. The attack vector is remote; a malicious actor can trigger the flaw by sending a crafted request containing the unauthenticated endpoint URL.
OpenCVE Enrichment