CVE-2022-25508 – freetakserver
Package
Manager: pip
Name: freetakserver
Vulnerable Version: >=0 <1.9.8.5
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS: 0.01412 pctl0.79801
Details
Improper Authentication in FreeTAKServer FreeTAKServer is an open source, lightweight Server for connect TAK clients. An access control issue in the component /ManageRoute/postRoute of FreeTAKServer version 1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. There is currently no known workaround. This issue was fixed in version 1.9.8.5.
Metadata
Created: 2022-03-12T00:00:37Z
Modified: 2024-09-20T21:03:38Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-hggv-mcp4-vxc5/GHSA-hggv-mcp4-vxc5.json
CWE IDs: ["CWE-287", "CWE-306"]
Alternative ID: GHSA-hggv-mcp4-vxc5
Finding: F006
Auto approve: 1