Impact
The vulnerability lies in the _blacklist function of maltrail's core/httpd.py, allowing remote execution of a request that bypasses authentication checks. This permits an unauthenticated attacker to modify or query the blacklist without authorization, potentially enabling further malicious network activity. The weakness is classified as CWE-287 (Authentication Failure) and CWE-306 (Missing Authentication for Critical Function).
Affected Systems
Stamparm's maltrail versions up to and including 3.0.1 are affected. The flaw exists in the Blacklist Endpoint component; all deployments running these releases are susceptible until the upgrade to 3.1, which gates the endpoint with authenticated sessions or the new Blacklist_ALLOWLIST option.
Risk and Exploitability
The CVSS base score of 6.9 indicates moderate impact, and the EPSS score of less than 1 % suggests low exploitation probability at present. The vulnerability is not listed in the CISA KEV catalog. Attackers can target any machine exposing the unsanitized / is possible; no additional privileges are required beyond standard network connectivity.
OpenCVE Enrichment