PT-2026-93814 · Git+1 · Hippo4J
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Hippo4j versions prior to 1.5.1
Description
Authenticated attackers can trigger outbound GET requests to internal networks and cloud metadata services. This occurs because four ThreadPoolController endpoints fail to validate the
clientAddress parameter, allowing the supply of arbitrary hostnames and ports. This issue is a server-side request forgery, which is a flaw that allows an attacker to induce the server-side application to make requests to an unintended location.Recommendations
Update to a version newer than 1.5.0.
Avoid using the
clientAddress parameter in the ThreadPoolController endpoints until the update is applied.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hippo4J