Impact
The vulnerability allows an unauthenticated attacker to inject arbitrary URLs into the x-base-url header or baseUrl request parameter. Because OpenMAIC skips URL validation in non‑production builds, the application forwards the request to the specified URL, enabling the attacker to retrieve sensitive cloud instance metadata and any credentials stored there. This weakness can lead to disclosure of privileged information and potential privilege escalation, affecting confidentiality and integrity of systems that rely on the exposed cloud environment.
Affected Systems
The affected product is THU‑MAIC OpenMAIC, specifically all releases prior to version 1.0.1, including the 1.0.0 release. The problem occurs when the application is built in a non‑production environment, meaning any environment that does not enforce the build‑time gating of URL validation.
Risk and Exploitability
The CVSS score of 9 indicates high severity. The EPSS score is not available, so the exact likelihood of exploitation is unknown, but the absence of a KEV listing means there is no publicly reported exploit yet. The likely attack vector is remote HTTP requests to the application's endpoint that accepts the x-base-url or baseUrl values. An attacker does not need authentication or special privileges to exploit the flaw, making the risk tangible for publicly accessible instances.
OpenCVE Enrichment