CVE-2022-23464 describes a Server-Side Request Forgery (SSRF) vulnerability in Nepxion Discovery, a Spring Cloud solution. The vulnerability, stemming from RouterResourceImpl's use of user-controlled input in RestTemplate's getForEntity, can lead to information disclosure. With a CVSS score of 7.5 (HIGH), it is easily exploitable over the network with no user interaction required, posing a significant risk of data compromise. There is currently no patch or known workaround, and while no public exploits or active exploitation have been observed, its low EPSS score suggests it is not widely targeted.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.16.2CPE matchmatch criteria | cpe:2.3:a:nepxion:discovery:*:*:*:*:*:spring_cloud:*:* | ||
>= 6.16.2, <= 6.16.2CPE match | cpe:2.3:a:nepxion:discovery:*:*:*:*:*:spring_cloud:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.