CVE-2023-27162: SSRF
openapi-generator up to v6.4.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/gen/clients/{language}. This vulnerability allows attackers to access network resources and sensitive information via a crafted API request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-27162?
CVE-2023-27162 is categorized as a critical severity vulnerability due to its potential for exploitation through Server-Side Request Forgery.
How do I fix CVE-2023-27162?
To fix CVE-2023-27162, upgrade the openapi-generator to version 6.5.0 or later.
What are the consequences of CVE-2023-27162?
If exploited, CVE-2023-27162 allows attackers to gain unauthorized access to network resources and sensitive information.
Which versions of openapi-generator are affected by CVE-2023-27162?
CVE-2023-27162 affects openapi-generator versions up to and including 6.4.0.
Is CVE-2023-27162 a known vulnerability?
Yes, CVE-2023-27162 is a known vulnerability that has been publicly documented and reported.