Metrics
Affected Vendors & Products
Thu, 04 Dec 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:orionsec:orion-ops:*:*:*:*:*:*:*:* |
Mon, 01 Dec 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Orionsec
Orionsec orion-ops |
|
| Vendors & Products |
Orionsec
Orionsec orion-ops |
Mon, 01 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Dec 2025 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected is the function MachineKeyController of the file orion-ops-api/orion-ops-web/src/main/java/cn/orionsec/ops/controller/MachineKeyController.java of the component API. The manipulation results in improper authorization. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | orionsec orion-ops API MachineKeyController.java MachineKeyController improper authorization | |
| Weaknesses | CWE-266 CWE-285 |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-12-01T04:32:06.185Z
Updated: 2025-12-01T14:47:45.470Z
Reserved: 2025-11-30T14:25:14.519Z
Link: CVE-2025-13807
Updated: 2025-12-01T14:47:34.167Z
Status : Analyzed
Published: 2025-12-01T05:16:02.987
Modified: 2025-12-04T20:24:06.027
Link: CVE-2025-13807
No data.