CVE-2025-58441: Knowage is vulnerable to blind server-side request forgery (SSRF)
Knowage is an open source analytics and business intelligence suite. Prior to version 8.1.37, there is a blind server-side request forgery vulnerability. The vulnerability allows attackers to send requests to arbitrary hosts/paths. Since the attacker is not able to read the response, the impact of this vulnerability is limited. However, an attacker should be able to leverage this vulnerability to scan the internal network. This issue has been patched in version 8.1.37.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58441?
CVE-2025-58441 is classified as a high severity vulnerability due to its ability to exploit blind server-side request forgery.
How do I fix CVE-2025-58441?
To fix CVE-2025-58441, upgrade to Knowage version 8.1.37 or later.
What is a blind server-side request forgery in the context of CVE-2025-58441?
A blind server-side request forgery allows an attacker to send unauthorized requests to other servers while being unable to see the responses.
Which versions of Knowage are affected by CVE-2025-58441?
CVE-2025-58441 affects Knowage versions prior to 8.1.37.
Can CVE-2025-58441 be exploited remotely?
Yes, CVE-2025-58441 can be exploited remotely by attackers to send requests to arbitrary hosts.