Metrics
Affected Vendors & Products
Mon, 01 Dec 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Orionsec
Orionsec orion-ops |
|
| Vendors & Products |
Orionsec
Orionsec orion-ops |
Mon, 01 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Dec 2025 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected is the function MachineKeyController of the file orion-ops-api/orion-ops-web/src/main/java/cn/orionsec/ops/controller/MachineKeyController.java of the component API. The manipulation results in improper authorization. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | orionsec orion-ops API MachineKeyController.java MachineKeyController improper authorization | |
| Weaknesses | CWE-266 CWE-285 |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-12-01T04:32:06.185Z
Updated: 2025-12-01T14:47:45.470Z
Reserved: 2025-11-30T14:25:14.519Z
Link: CVE-2025-13807
Updated: 2025-12-01T14:47:34.167Z
Status : Awaiting Analysis
Published: 2025-12-01T05:16:02.987
Modified: 2025-12-01T15:39:33.110
Link: CVE-2025-13807
No data.