Impact
Quickwit through 0.9.0 fails to validate the host and scheme of the queue_url parameter in SQS file sources, allowing attackers to make the node issue requests to arbitrary internal addresses. The flaw, identified as CWE-918, enables an attacker to supply a malicious queue_url to the create-source API, which can be used to probe internal networks and fingerprint services based on connection responses. This leads to a loss of confidentiality for internal resources and could serve as a stepping stone for further exploitation.
Affected Systems
The vulnerability affects the open-source Quickwit (oss) product released through version 0.9.0 and earlier. Any deployment of Quickwit that exposes the create-source API to untrusted users is susceptible, regardless of the operating system or cloud provider. The issue is documented in Quickwit OSS source repositories and tracks.
Risk and Exploitability
The CVSS score of 8.7 classifies this as High severity. The EPSS score of under 1% indicates that active exploitation is currently rare, but the lack of a KEV listing does not reduce risk for environments where Quickwit is exposed. Attackers can mount this attack from any system that can call the exposed API, making it feasible with remote access. Exploitation requires the ability to submit a source creation request; no special privileges beyond API access are needed. The impact is limited to internal network reconnaissance, but could assist in more damaging attacks if the attacker later gains privileged access.
OpenCVE Enrichment