VDB
Sign up
CRITICAL9.8

GHSA-gqj2-324p-vx73

Microcks contains a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download

Quick fix

GHSA-gqj2-324p-vx73 — io.github.microcks:microcks: upgrade to the fixed version with the command below.

# pom.xml: bump <version>1.17.1</version> for io.github.microcks:microcks

Details

Microcks up to version 1.17.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/io.github.microcks:microcks
Introduced in: 0Fixed in: 1.17.1
Fix# pom.xml: bump <version>1.17.1</version> for io.github.microcks:microcks

References