Raven is an open-source messaging platform. A vulnerability allowed any logged in user to execute code via an API endpoint. This vulnerability is fixed in 2.1.10.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 01 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Raven is an open-source messaging platform. A vulnerability allowed any logged in user to execute code via an API endpoint. This vulnerability is fixed in 2.1.10. | |
| Title | Raven allows Remote Code Execution due to improper validation | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-04-01T15:06:36.426Z
Updated: 2025-04-01T15:46:48.578Z
Reserved: 2025-03-26T15:04:52.627Z
Link: CVE-2025-31132
Updated: 2025-04-01T15:45:17.228Z
Status : Awaiting Analysis
Published: 2025-04-01T15:16:07.987
Modified: 2025-04-01T20:26:11.547
Link: CVE-2025-31132
No data.