Oxidized Web RANCID migration page allows unauthenticated user to gain control over Linux user account
Critical severity
GitHub Reviewed
Published
Mar 3, 2025
to the GitHub Advisory Database
•
Updated Mar 3, 2025
Description
Published by the National Vulnerability Database
Mar 3, 2025
Published to the GitHub Advisory Database
Mar 3, 2025
Reviewed
Mar 3, 2025
Last updated
Mar 3, 2025
In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain control over the Linux user account that is running oxidized-web.
References