CVE-2024-48107

MEDIUM

sparkshop <= 1.1.7 - Server-Side Request Forgery

Title source: llm
STIX 2.1

Description

SparkShop <=1.1.7 is vulnerable to server-side request forgery (SSRF). This vulnerability allows attacks to scan ports on the Intranet or local network where the server resides, attack applications running on the Intranet or local network, or read metadata on the cloud server.

Scores

CVSS v3 6.5
EPSS 0.0022
EPSS Percentile 12.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (1)
sparkshop/sparkshop < 1.1.7
Published Oct 28, 2024
Tracked Since Feb 18, 2026