CVE-2023-27162 is a critical Server-Side Request Forgery (SSRF) vulnerability affecting OpenAPI Generator up to version 6.4.0, specifically within the /api/gen/clients/{language} component. This flaw allows unauthenticated attackers to craft API requests that can access internal network resources and sensitive information, posing a significant risk to confidentiality and integrity. With a CVSS score of 9.1 (CRITICAL), it indicates a network-based attack with low complexity and no user interaction required. While no active exploits, Metasploit modules, or public exploit code are currently reported, and community discussion is minimal, the high severity warrants immediate attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.4.0CPE matchmatch criteria | cpe:2.3:a:openapi-generator:openapi_generator:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.