CVE-2025-14518: PowerJob Network Request PingPongUtils.java checkConnectivity server-side request forgery
A vulnerability was identified in PowerJob up to 5.1.2. This vulnerability affects the function checkConnectivity of the file src/main/java/tech/powerjob/common/utils/net/PingPongUtils.java of the component Network Request Handler. The manipulation of the argument targetIp/targetPort leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14518?
CVE-2025-14518 is classified as a medium severity vulnerability affecting PowerJob versions up to 5.1.2.
How do I fix CVE-2025-14518?
To fix CVE-2025-14518, upgrade PowerJob to version 5.1.3 or later.
What does CVE-2025-14518 affect?
CVE-2025-14518 affects the checkConnectivity function in the Network Request Handler of PowerJob.
Is my version of PowerJob vulnerable to CVE-2025-14518?
If you are using PowerJob version 5.1.2 or earlier, your version is vulnerable to CVE-2025-14518.
How can CVE-2025-14518 be exploited?
CVE-2025-14518 can be exploited through manipulation of the targetIp/targetPort arguments in network connectivity checks.