Impact
Hippo4j through version 1.5.0 implements four ThreadPoolController endpoints that do not validate the clientAddress argument supplied by authenticated callers. The flaw allows an attacker who can authenticate to the application to cause the server to issue outbound HTTP GET requests to arbitrary hostnames and ports. This type of server‑side request forgery can expose internal resources, permit enumeration of the internal network, or retrieve cloud provider metadata services, potentially revealing sensitive configuration or credentials. The vulnerability is categorized as CWE‑918.
Affected Systems
The affected product is Hippo4j, maintained by Opengoofy, in all releases up to and including 1.5.0. The flaw resides in the ThreadPoolController in both the hippo4j-auth and hippo4j-console modules. Users running any version of Hippo4j before 1.5.0 that exposes these endpoints and allows authenticated access are vulnerable.
Risk and Exploitability
The Common Vulnerability Scoring System assigns a score of 5.3, indicating a medium‑level impact. The Exploit Prediction Scoring System shows an exploitation probability of less than 1 %, reflecting the need for valid credentials and specific endpoint access, reducing the likelihood of widespread abuse. Hippo4j is not listed in the CISA Known Exploited Vulnerabilities catalog. The flaw is exploitable from an authenticated context on any host where the application is reachable; attackers can supply arbitrary hostnames and ports to trigger outbound GET requests to internal networks or cloud metadata services.
OpenCVE Enrichment