Impact
A vulnerability exists in the scaleImage function within the NASA Earthdata-Search 1.0.0 component. The flaw allows an unauthenticated attacker to craft a request that causes the server to perform arbitrary HTTP requests, exposing the service to server‑side request forgery. This can enable the attacker to access internal resources, exfiltrate data, or use the system as a proxy for further attacks.
Affected Systems
NASA Earthdata‑Search version 1.0.0 is affected. The vulnerability resides in the scale Endpoint handler located at serverless/src/scaleImage/handler.js.
Risk and Exploitability
With a CVSS score of 6.9, the exploit is considered moderate severity. EPSS is not available and the vulnerability is not listed in CISA KEV. The attack can be initiated remotely without authentication, making it easily exploitable. Since the exploit is publicly disclosed, the likelihood of use is non‑negligible.
OpenCVE Enrichment