-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from RouterResourceImpl.getRouterEntityList method which directly incorporates user-controlled input into a URL construction (routeProtocol://routeHost:routePort/...) and executes a server-side request via RestTemplate. This allows attackers to manipulate the URL to access internal resources or external systems. The code structure shown in security advisories confirms direct parameter concatenation into the URL and subsequent HTTP request execution without validation mechanisms.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| com.nepxion:discovery | maven | <= 6.16.2 |
KEV Misses 88% of Exploited CVEs- Get the report