Server-Side Request Forgery in Microcks by Microcks
CVE-2023-48910
9.8CRITICAL
What is CVE-2023-48910?
Microcks, a tool designed for API mocking and testing, was found to have a Server-Side Request Forgery (SSRF) vulnerability affecting versions up to 1.17.1. This flaw arises from improper handling of requests in the components located at /jobs and /artifact/download. By crafting a manipulated GET request, an attacker could exploit this vulnerability to gain unauthorized access to network resources and potentially sensitive information hosted on internal servers.
