Impact
A server‑side request forgery flaw exists in Tanium Threat Response that allows an attacker to cause the server to send arbitrary HTTP requests on its behalf. This could enable data leakage, credential theft, or the execution of unintended actions on other hosts. The weakness is identified as CWE‑918.
Affected Systems
The vulnerability affects the Tanium Threat Response product. No specific version information is provided, so any deployment of Tanium Threat Response that has not yet received the vendor’s fix is potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate-to‑high risk, while the EPSS score is listed as less than 1 percent, suggesting a low probability of exploitation at the time of this analysis. The vulnerability is not included in CISA’s KEV catalog. Attackers would need to send tailored requests to the Threat Response server, likely requiring valid authentication, to trigger malicious outbound connections. Although exploitation evidence is limited, the nature of SRF makes the risk rise if the server can reach sensitive internal or external resources.
OpenCVE Enrichment