Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:45448
HistoryFeb 12, 2024 - 12:45 p.m.

Drive-by Localhost Attack

2024-02-1212:45:05
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
micronaut
server
vulnerable
drive-by localhost attack
localhost
attack
vulnerability
management endpoints
http requests
compromised websites
cors
preflight checks
security measures

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

6.9 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.0%

micronaut server is vulnerable to Drive-by Localhost Attack. The vulnerability is caused when unsecured management endpoints are enabled, which are susceptible to malicious HTTP requests from a compromised websites targeting localhost (drive by localhost attack). The issue arises because some requests are “simple” and bypass CORS preflight checks, making these endpoints vulnerable when enabled without proper security measures.

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

6.9 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.0%

Related for VERACODE:45448