Impact
DataGear versions up to 6.0.0 contain a server‑side request forgery vulnerability in the /dataSet/preview/Http endpoint. The flaw accepts a caller‑controlled URI and performs the specified GET, POST, PUT, PATCH, or DELETE request on the server, returning the full response body without any authentication or validation. This allows an attacker to reach internal network endpoints or cloud metadata services and obtain sensitive data or internal system information.
Affected Systems
The affected product is DataGear from datageartech, specifically all releases through version 6.0.0. No later releases are mentioned in the advisory.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8, classifying it as high severity. The EPSS score is less than 1%, indicating a very low probability of exploitation based on current data, and it is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers can exploit the flaw over the network without authentication; the endpoint must be reachable by the attacker. Successful exploitation can lead to the disclosure of internal configuration or sensitive data accessed via the SSRF capability.
OpenCVE Enrichment