Vulnerabilities > CVE-2023-27162 - Server-Side Request Forgery (SSRF) vulnerability in Openapi-Generator Openapi Generator
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
NONE Summary
openapi-generator up to v6.4.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/gen/clients/{language}. This vulnerability allows attackers to access network resources and sensitive information via a crafted API request.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- http://openapi-generator.com
- http://openapi-generator.com
- https://gist.github.com/b33t1e/6121210ebd9efd4f693c73b830d8ab08
- https://gist.github.com/b33t1e/6121210ebd9efd4f693c73b830d8ab08
- https://github.com/OpenAPITools/openapi-generator
- https://github.com/OpenAPITools/openapi-generator
- https://notes.sjtu.edu.cn/s/2_yki_2Xq
- https://notes.sjtu.edu.cn/s/2_yki_2Xq