Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-54955

Опубликовано: 03 авг. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 8.1

Описание

OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition (EE) before 6.10.3 have a critical FireEdge race condition that can lead to full account takeover. By exploiting this, an unauthenticated attacker can obtain a valid JSON Web Token (JWT) belonging to a legitimate user without knowledge of their credentials.

РелизСтатусПримечание
devel

DNE

esm-apps/bionic

needs-triage

esm-apps/xenial

needs-triage

jammy

DNE

noble

DNE

plucky

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 24%
0.00078
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
8 дней назад

OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition (EE) before 6.10.3 have a critical FireEdge race condition that can lead to full account takeover. By exploiting this, an unauthenticated attacker can obtain a valid JSON Web Token (JWT) belonging to a legitimate user without knowledge of their credentials.

CVSS3: 8.1
debian
8 дней назад

OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition ...

CVSS3: 8.1
github
8 дней назад

OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition (EE) before 6.10.3 have a critical FireEdge race condition that can lead to full account takeover. By exploiting this, an unauthenticated attacker can obtain a valid JSON Web Token (JWT) belonging to a legitimate user without knowledge of their credentials.

EPSS

Процентиль: 24%
0.00078
Низкий

8.1 High

CVSS3