LogStare Collector contains an incorrect authorization vulnerability in UserRegistration. If exploited, a non-administrative user may create a new user account by sending a crafted HTTP request.
Metrics
Affected Vendors & Products
References
History
Thu, 04 Dec 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linux linux Kernel
Secuavail Secuavail logstare Collector |
|
| CPEs | cpe:2.3:a:secuavail:logstare_collector:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Linux linux Kernel
Secuavail Secuavail logstare Collector |
Mon, 24 Nov 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linux
Linux linux Logstare Logstare collector Microsoft Microsoft windows |
|
| Vendors & Products |
Linux
Linux linux Logstare Logstare collector Microsoft Microsoft windows |
Fri, 21 Nov 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 21 Nov 2025 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LogStare Collector contains an incorrect authorization vulnerability in UserRegistration. If exploited, a non-administrative user may create a new user account by sending a crafted HTTP request. | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: jpcert
Published: 2025-11-21T06:17:56.472Z
Updated: 2025-11-21T14:58:09.579Z
Reserved: 2025-11-10T08:14:00.950Z
Link: CVE-2025-62189
Updated: 2025-11-21T14:53:57.811Z
Status : Analyzed
Published: 2025-11-21T07:15:54.507
Modified: 2025-12-04T16:30:38.350
Link: CVE-2025-62189
No data.