Knowage is an open source analytics and business intelligence suite. Prior to version 8.1.37, Knowage is vulnerable to server-side request forgery. The vulnerability allows attackers to send requests to arbitrary hosts/paths. Since the attacker is not able to read the response, the impact of this vulnerability is limited. However, an attacker could be able to leverage this vulnerability to scan the internal network. This issue has been patched in version 8.1.37.
History

Fri, 05 Sep 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Eng
Eng knowage
CPEs cpe:2.3:a:eng:knowage:*:*:*:*:*:*:*:*
Vendors & Products Eng
Eng knowage

Tue, 02 Sep 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 01 Sep 2025 16:00:00 +0000

Type Values Removed Values Added
Description Knowage is an open source analytics and business intelligence suite. Prior to version 8.1.37, Knowage is vulnerable to server-side request forgery. The vulnerability allows attackers to send requests to arbitrary hosts/paths. Since the attacker is not able to read the response, the impact of this vulnerability is limited. However, an attacker could be able to leverage this vulnerability to scan the internal network. This issue has been patched in version 8.1.37.
Title Knowage vulnerable to server-side request forgery
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-09-01T15:46:04.915Z

Updated: 2025-09-02T18:15:03.646Z

Reserved: 2025-08-04T17:34:24.421Z

Link: CVE-2025-55007

cve-icon Vulnrichment

Updated: 2025-09-02T18:12:30.061Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-01T16:15:31.370

Modified: 2025-09-05T17:57:12.773

Link: CVE-2025-55007

cve-icon Redhat

No data.