CRITICAL9.8
GHSA-gqj2-324p-vx73
Microcks contains a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download
Quick fix
GHSA-gqj2-324p-vx73 — io.github.microcks:microcks: upgrade to the fixed version with the command below.
# pom.xml: bump <version>1.17.1</version> for io.github.microcks:microcksDetails
Microcks up to version 1.17.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/io.github.microcks:microcks
Introduced in:
0Fixed in: 1.17.1Fix
# pom.xml: bump <version>1.17.1</version> for io.github.microcks:microcks