First published: Fri Mar 31 2023(Updated: )
openapi-generator up to v6.4.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/gen/clients/{language}. This vulnerability allows attackers to access network resources and sensitive information via a crafted API request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
npm | <=6.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-27162 is categorized as a critical severity vulnerability due to its potential for exploitation through Server-Side Request Forgery.
To fix CVE-2023-27162, upgrade the openapi-generator to version 6.5.0 or later.
If exploited, CVE-2023-27162 allows attackers to gain unauthorized access to network resources and sensitive information.
CVE-2023-27162 affects openapi-generator versions up to and including 6.4.0.
Yes, CVE-2023-27162 is a known vulnerability that has been publicly documented and reported.