Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS1oZ2d2LW1jcDQtdnhjNc0ydA

Improper Authentication in FreeTAKServer

FreeTAKServer is an open source, lightweight Server for connect TAK clients. An access control issue in the component /ManageRoute/postRoute of FreeTAKServer version 1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. There is currently no known workaround. This issue was fixed in version 1.9.8.5.

Permalink: https://github.com/advisories/GHSA-hggv-mcp4-vxc5
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oZ2d2LW1jcDQtdnhjNc0ydA
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: about 2 years ago
Updated: 9 months ago


CVSS Score: 7.5
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Identifiers: GHSA-hggv-mcp4-vxc5, CVE-2022-25508
References: Repository: https://github.com/FreeTAKTeam/FreeTakServer
Blast Radius: 2.3

Affected Packages

pypi:FreeTAKServer
Dependent packages: 0
Dependent repositories: 2
Downloads: 2,224 last month
Affected Version Ranges: <= 1.9.8
Fixed in: 1.9.8.5
All affected versions: 0.1.0, 0.1.1, 0.1.2, 0.1.3, 0.1.4, 0.1.5, 0.1.6, 0.1.8, 0.1.9, 0.8.13, 0.8.19, 0.8.20, 0.8.21, 0.8.22, 0.8.23, 0.8.50, 0.8.75, 0.8.76, 0.9.9, 1.0.3, 1.1.1, 1.1.2, 1.2.5, 1.5.10, 1.5.12, 1.7.1, 1.7.5, 1.8.1, 1.9.1, 1.9.5, 1.9.6, 1.9.7, 1.9.8
All unaffected versions: 1.9.9, 2.0.21, 2.0.66, 2.0.69, 2.1.1, 2.1.2, 2.1.3