Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS1oZ2d2LW1jcDQtdnhjNc0ydA
Improper Authentication in FreeTAKServer
FreeTAKServer is an open source, lightweight Server for connect TAK clients. An access control issue in the component /ManageRoute/postRoute of FreeTAKServer version 1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. There is currently no known workaround. This issue was fixed in version 1.9.8.5.
Permalink: https://github.com/advisories/GHSA-hggv-mcp4-vxc5JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oZ2d2LW1jcDQtdnhjNc0ydA
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: about 2 years ago
Updated: 9 months ago
CVSS Score: 7.5
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Identifiers: GHSA-hggv-mcp4-vxc5, CVE-2022-25508
References:
- https://nvd.nist.gov/vuln/detail/CVE-2022-25508
- https://github.com/FreeTAKTeam/FreeTakServer/issues/291
- https://github.com/pypa/advisory-database/tree/main/vulns/freetakserver/PYSEC-2022-43054.yaml
- https://github.com/advisories/GHSA-hggv-mcp4-vxc5
Blast Radius: 2.3
Affected Packages
pypi:FreeTAKServer
Dependent packages: 0Dependent repositories: 2
Downloads: 2,224 last month
Affected Version Ranges: <= 1.9.8
Fixed in: 1.9.8.5
All affected versions: 0.1.0, 0.1.1, 0.1.2, 0.1.3, 0.1.4, 0.1.5, 0.1.6, 0.1.8, 0.1.9, 0.8.13, 0.8.19, 0.8.20, 0.8.21, 0.8.22, 0.8.23, 0.8.50, 0.8.75, 0.8.76, 0.9.9, 1.0.3, 1.1.1, 1.1.2, 1.2.5, 1.5.10, 1.5.12, 1.7.1, 1.7.5, 1.8.1, 1.9.1, 1.9.5, 1.9.6, 1.9.7, 1.9.8
All unaffected versions: 1.9.9, 2.0.21, 2.0.66, 2.0.69, 2.1.1, 2.1.2, 2.1.3