{"id":"GHSA-gqj2-324p-vx73","summary":"Microcks contains a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download","details":"Microcks up to version 1.17.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.","aliases":["CVE-2023-48910"],"modified":"2026-08-24T00:35:42.135858566Z","published":"2023-12-04T18:30:32Z","database_specific":{"github_reviewed_at":"2023-12-04T23:14:01Z","nvd_published_at":"2023-12-04T17:15:07Z","cwe_ids":["CWE-918"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-48910"},{"type":"WEB","url":"https://gist.github.com/b33t1e/2a2dc17cf36cd741b2c99425c892d826"},{"type":"PACKAGE","url":"https://github.com/microcks/microcks"},{"type":"WEB","url":"https://github.com/orgs/microcks/discussions/892"}],"affected":[{"package":{"name":"io.github.microcks:microcks","ecosystem":"Maven","purl":"pkg:maven/io.github.microcks/microcks"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.17.1"}]}],"versions":["0.1.3","0.5.0","0.6.0","0.6.1","0.7.0","0.7.1","0.8.0","0.9.0","0.9.1","0.9.2","1.0.0","1.0.0-RC1","1.1.0","1.1.1","1.10.0","1.10.0-fix-1","1.10.1","1.10.1-fix-1","1.11.0","1.11.0-fix-2","1.11.0-fix-3","1.11.1","1.11.2","1.12.0","1.12.1","1.13.0","1.13.1","1.13.2","1.14.0","1.14.0-rc1","1.14.0-rc2","1.15.0","1.15.0-rc1","1.2.0","1.2.1","1.3.0","1.4.0","1.4.1","1.4.1-fix-1","1.4.1-fix-2","1.5.0","1.5.0-RC1","1.5.0-RC2","1.5.1","1.5.1-RC1","1.5.1-fix-1","1.5.2","1.5.2-RC1","1.6.0","1.6.0-RC1","1.6.0-fix-1","1.6.0-fix-2","1.6.1","1.7.0","1.7.0-RC1","1.7.1","1.7.1-fix-1","1.8.0","1.8.0-fix-1","1.8.1","1.8.1-M1","1.9.0","1.9.0-fix-1","1.9.0-fix-2","1.9.1","1.9.1-fix-1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/12/GHSA-gqj2-324p-vx73/GHSA-gqj2-324p-vx73.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}