Impact
A server‑side request forgery flaw in Progress MarkLogic Server permits a logged‑in user with low‑privileged roles to transmute outbound requests to cloud instance metadata endpoints. By doing so an attacker can read the credentials stored on the host and use them to compromise resources that belong to the same cloud account. The vulnerability is a classic example of remote code‑execution‑level access to cloud secrets, and is identified as CWE‑918.
Affected Systems
MarkLogic Server from Progress Software Corporation is affected if the instance is running a version prior to 11.3.6 or 12.0.3. Only authenticated users with roles that do not normally include network‑access privileges can exploit the flaw.
Risk and Exploitability
The CVSS score of 8.5 classifies this flaw as high‑severity and indicates significant impact. EPSS is not available, and the vulnerability is not currently listed in a CISA KEV publication. The likely attack vector is an authenticated user with low‑privileged roles who can bypass cloud metadata protection. Once misused, the attacker may read cloud credentials and subsequently gain control over cloud resources that are accessible to the host machine.
OpenCVE Enrichment