CVE-2020-1925

HIGH

Apache Olingo 4.0.0-4.7.0 - Server-Side Request Forgery via Location Header

Title source: llm
STIX 2.1

Description

Apache Olingo versions 4.0.0 to 4.7.0 provide the AsyncRequestWrapperImpl class which reads a URL from the Location header, and then sends a GET or DELETE request to this URL. It may allow to implement a SSRF attack. If an attacker tricks a client to connect to a malicious server, the server can make the client call any URL including internal resources which are not directly accessible by the attacker.

Scores

CVSS v3 7.5
EPSS 0.0118
EPSS Percentile 79.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-918
Status published
Products (2)
apache/olingo 4.0.0 - 4.7.0
org.apache.olingo/odata-client-core 4.0.0 - 4.7.1Maven
Published Jan 09, 2020
Tracked Since Feb 18, 2026