Impact
The flaw allows an attacker who can control a client‑metadata URL and its DNS to force the application server to resolve IPv6 addresses that are actually internal, such as ::127.0.0.1 or fec0::/10, and then fetch data from those internal targets. This violates the intended outbound policy and permits the attacker to reach loopback or intranet services, potentially exfiltrating sensitive data or using the server as a pivot for deeper attacks. The weakness is a classic Server‑Side Request Forgery (CWE‑918).
Affected Systems
The vulnerability exists in ash-project ash_authentication_oauth2_server version 0.3.0 only. The CVE does not specify a fixed release, so vendors should verify that they are running a patched version.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. Although EPSS information is not provided and the vulnerability is not listed in the CISA KEV catalog, the remote nature of the SSRF makes exploitation plausible for an attacker who can manipulate the client‑metadata URL. The attack requires only the ability to supply a malicious URL to the server; no authentication is mentioned, implying that any user able to register or update client metadata could trigger it. Should the server expose internal resources, the impact could be significant, though the current scoring reflects a moderate risk level.
OpenCVE Enrichment