CVE-2025-14518
Severity CVSS v4.0:
MEDIUM
Type:
CWE-918
Server-Side Request Forgery (SSRF)
Publication date:
11/12/2025
Last modified:
11/12/2025
Description
A vulnerability was identified in PowerJob up to 5.1.2. This vulnerability affects the function checkConnectivity of the file src/main/java/tech/powerjob/common/utils/net/PingPongUtils.java of the component Network Request Handler. The manipulation of the argument targetIp/targetPort leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Impact
Base Score 4.0
5.30
Severity 4.0
MEDIUM
Base Score 3.x
6.30
Severity 3.x
MEDIUM
Base Score 2.0
6.50
Severity 2.0
MEDIUM
References to Advisories, Solutions, and Tools
- https://github.com/PowerJob/PowerJob/issues/1144
- https://github.com/PowerJob/PowerJob/issues/1144#issue-3673393002
- https://vuldb.com/?ctiid_335856=
- https://vuldb.com/?id_335856=
- https://vuldb.com/?submit_702896=
- https://github.com/PowerJob/PowerJob/issues/1144
- https://github.com/PowerJob/PowerJob/issues/1144#issue-3673393002



