logo

CVE-2022-25508 freetakserver

Package

Manager: pip
Name: freetakserver
Vulnerable Version: >=0 <1.9.8.5

Severity

Level: High

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

EPSS: 0.01412 pctl0.79801

Details

Improper Authentication in FreeTAKServer FreeTAKServer is an open source, lightweight Server for connect TAK clients. An access control issue in the component /ManageRoute/postRoute of FreeTAKServer version 1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. There is currently no known workaround. This issue was fixed in version 1.9.8.5.

Metadata

Created: 2022-03-12T00:00:37Z
Modified: 2024-09-20T21:03:38Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-hggv-mcp4-vxc5/GHSA-hggv-mcp4-vxc5.json
CWE IDs: ["CWE-287", "CWE-306"]
Alternative ID: GHSA-hggv-mcp4-vxc5
Finding: F006
Auto approve: 1