OSV 1.4.0 · github-reviewed · 修改于 2026-05-12 00:23
发布时间
2026-05-06 02:33
GitHub 审查时间
2026-05-12 00:23
NVD 发布时间
2026-05-06 00:16
源文件
advisories/github-reviewed/2026/05/GHSA-gx3v-wxfj-8h24/GHSA-gx3v-wxfj-8h24.json
In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, the Operation Delegation feature fails to validate the destination URI of delegated requests. An unauthenticated remote attacker can exploit this design flaw to force the BaSyx server to execute blind HTTP POST requests to arbitrary internal or external targets. This allows an attacker to bypass network segmentation and pivot into isolated internal IT/OT infrastructure or target Cloud Metadata services (IMDS).