Knowage is an open source analytics and business intelligence suite. Prior to version 8.1.37, there is a blind server-side request forgery vulnerability. The vulnerability allows attackers to send requests to arbitrary hosts/paths. Since the attacker is not able to read the response, the impact of this vulnerability is limited. However, an attacker should be able to leverage this vulnerability to scan the internal network. This issue has been patched in version 8.1.37.
Metrics
Affected Vendors & Products
References
History
Thu, 08 Jan 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Knowage-suite
Knowage-suite knowage |
|
| Vendors & Products |
Knowage-suite
Knowage-suite knowage |
Wed, 07 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 Jan 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Knowage is an open source analytics and business intelligence suite. Prior to version 8.1.37, there is a blind server-side request forgery vulnerability. The vulnerability allows attackers to send requests to arbitrary hosts/paths. Since the attacker is not able to read the response, the impact of this vulnerability is limited. However, an attacker should be able to leverage this vulnerability to scan the internal network. This issue has been patched in version 8.1.37. | |
| Title | Knowage is vulnerable to blind server-side request forgery (SSRF) | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-07T18:21:35.951Z
Reserved: 2025-09-01T20:03:06.532Z
Link: CVE-2025-58441
Updated: 2026-01-07T18:21:26.479Z
Status : Awaiting Analysis
Published: 2026-01-07T18:15:49.313
Modified: 2026-01-08T18:08:54.147
Link: CVE-2025-58441
No data.
OpenCVE Enrichment
Updated: 2026-01-08T09:48:34Z