PT-2026-93811 · Datageartech+1 · Datagear
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
DataGear versions prior to 6.0.1
Description
An issue exists where unauthenticated attackers can execute arbitrary HTTP requests by providing a caller-controlled URI. This occurs via the '/dataSet/preview/Http' endpoint, allowing the issuance of GET, POST, PUT, PATCH, or DELETE requests to internal endpoints and cloud metadata services. The attacker can receive full response bodies without authentication or validation. This is a server-side request forgery (SSRF), which is a flaw that allows an attacker to induce the server-side application to make requests to an unintended location.
Recommendations
Update DataGear to a version newer than 6.0.0.
Restrict access to the '/dataSet/preview/Http' endpoint to minimize the risk of exploitation.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Datagear