CVE-2025-55007: Knowage vulnerable to server-side request forgery
Knowage is an open source analytics and business intelligence suite. Prior to version 8.1.37, Knowage is vulnerable to server-side request forgery. The vulnerability allows attackers to send requests to arbitrary hosts/paths. Since the attacker is not able to read the response, the impact of this vulnerability is limited. However, an attacker could be able to leverage this vulnerability to scan the internal network. This issue has been patched in version 8.1.37.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55007?
CVE-2025-55007 is classified as a medium severity vulnerability due to its potential for exploitation through server-side request forgery.
How do I fix CVE-2025-55007?
To fix CVE-2025-55007, upgrade Knowage to version 8.1.37 or later.
What kind of attacks can CVE-2025-55007 enable?
CVE-2025-55007 enables attackers to perform server-side request forgery attacks, allowing them to send requests to arbitrary hosts/paths.
Which versions of Knowage are affected by CVE-2025-55007?
CVE-2025-55007 affects Knowage versions prior to 8.1.37.
Is a patch available for CVE-2025-55007?
Yes, a patch is available in Knowage version 8.1.37 which resolves the vulnerability.