NocoBase versions prior to 2.0.37 contain a Server-Side Request Forgery (SSRF) vulnerability in the workflow HTTP request plugin and custom request action plugin that fails to validate user-supplied URLs before making server-side HTTP requests. An authenticated attacker can exploit this flaw to access internal network services, cloud metadata endpoints, and localhost services that should not be accessible from the internet. The vulnerability requires user authentication but presents a moderate risk due to its potential to expose sensitive internal infrastructure and cloud credentials. The EPSS score of 0.00014 indicates very low real-world exploitability probability, and the vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog, suggesting no active exploitation in the wild. Organizations running NocoBase should upgrade to version 2.0.37 or later to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0.37CPE matchmatch criteria | cpe:2.3:a:nocobase:nocobase:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.