Executive Summary

Informations
Name CVE-2025-27101 First vendor Publication 2025-03-11
Vendor Cve Last vendor Modification 2025-03-12

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

Opal is OBiBa’s core database application for biobanks or epidemiological studies. Prior to version 5.1.1, when copying any parent directory to a folder in the /temp/ directory, all files in that parent directory are copied, including files which the user should not have access to. All users of the application are impacted, as this is exploitable by any user to reveal all files in the opal filesystem. This also means that low-privilege users such as DataShield users can retrieve the files of other users. Version 5.1.1 contains a patch for the issue.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-27101

Sources (Detail)

https://github.com/obiba/opal/commit/fca7dc9c8348064741b2e8b2c31b66660a935743
https://github.com/obiba/opal/security/advisories/GHSA-rxmx-gqjj-vhv8
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
Date Informations
2025-03-12 17:20:29
  • Multiple Updates
2025-03-12 05:41:26
  • First insertion