Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-15581

Опубликовано: 18 фев. 2026
Источник: debian

Описание

Orthanc versions before 1.12.10 are affected by an authorisation logic flaw in the application's HTTP Basic Authentication implementation. Successful exploitation could result in Privilege Escalation, potentially allowing full administrative access.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
orthancfixed1.12.10+dfsg-1package
orthancno-dsatrixiepackage
orthancno-dsabookwormpackage

Примечания

  • https://projectblack.io/blog/orthanc-1-12-9-user-impersonation/#exploitation

  • https://orthanc.uclouvain.be/bugs/show_bug.cgi?id=252

Связанные уязвимости

ubuntu
7 месяцев назад

Orthanc versions before 1.12.10 are affected by an authorisation logic flaw in the application's HTTP Basic Authentication implementation. Successful exploitation could result in Privilege Escalation, potentially allowing full administrative access.

nvd
7 месяцев назад

Orthanc versions before 1.12.10 are affected by an authorisation logic flaw in the application's HTTP Basic Authentication implementation. Successful exploitation could result in Privilege Escalation, potentially allowing full administrative access.

github
7 месяцев назад

Orthanc versions before 1.12.10 are affected by an authorisation logic flaw in the application's HTTP Basic Authentication implementation. Successful exploitation could result in Privilege Escalation, potentially allowing full administrative access.