Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-24888

Опубликовано: 13 фев. 2025
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

The SecureDrop Client is a desktop application for journalists to communicate with sources and work with submissions on the SecureDrop Workstation. Prior to version 0.14.1, a malicious SecureDrop Server could obtain code execution on the SecureDrop Client virtual machine (sd-app). SecureDrop Server itself has multiple layers of built-in hardening, and is a dedicated physical machine exposed on the internet only via Tor hidden services for the Source and Journalist interfaces, and optionally via remote SSH access over another Tor hidden service. A newsroom's SecureDrop Workstation communicates only with its own dedicated SecureDrop Server.

The SecureDrop Client runs in a dedicated Qubes virtual machine, named sd-app, as part of the SecureDrop Workstation. The private OpenPGP key used to decrypt submissions and replies is stored in a separate virtual machine and never accessed directly. The vulnerability lies in the code responsible for downloading replies. The filename of the reply

EPSS

Процентиль: 77%
0.00995
Низкий

8.1 High

CVSS3

Дефекты

CWE-22

EPSS

Процентиль: 77%
0.00995
Низкий

8.1 High

CVSS3

Дефекты

CWE-22