GHSA-68r5-9hpg-7qw9
CRITICALThe DSMLv2 SOAP gateway (opendj-dsml-servlet) in OpenIdentityPlatform OpenDJ through 5.1.1 dereferences attacker-supplied xsd:anyURI values server-side without a scheme allowlist, egress filtering, or a size cap, and is reachable without authentication by default. A remote unauthenticated attacker can submit a DSML add/modify request whose value is a URI to (1) perform server-side request forgery
- Affected
- <= 5.1.1
- Fixed in
- 5.1.2
- Weakness
- CWE-73
- Published
- 2026-07-24
- Source
- github