Impact
A flaw in the OpenSearchGranuleSearchLambda function allows an attacker to manipulate the openSearchOsdd argument, enabling SSRF. Remote exploitation is possible, as the vulnerability can be triggered from outside the network. This weakness falls under CWE‑918 and can expose internal network resources or enable further lateral movement.
Affected Systems
The impact is limited to NASA earthdata‑search version 1.0.0, specifically the granules endpoint handler found in serverless/src/openSearchGranuleSearch/handler.js. No other product versions have been reported as affected.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity level. The EPSS score is not available, so the exploitation probability is uncertain, although an exploit has already been published and is potentially in use. Because the vulnerability is not listed in the CISA KEV catalog, the risk does not carry that formal designation, yet the remote SSRF capability raises a significant threat to data confidentiality and network integrity.
OpenCVE Enrichment