THREAT OPS › Threat News › [GHSA] GHSA-pqqc-8v73-9gg2 (medium) — LF Edge eKuiper: SSRF in External Service
[GHSA] GHSA-pqqc-8v73-9gg2 (medium) — LF Edge eKuiper: SSRF in External Service
GHSA-pqqc-8v73-9gg2 Severity: medium CVE: CVE-2025-24979
LF Edge eKuiper: SSRF in External Service
### Summary Server-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or clo
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2025-24979cve
- http://127.0.0.1:9081`url
- http://127.0.0.1:9081url
Original source: https://github.com/advisories/GHSA-pqqc-8v73-9gg2