CVE-2025-25182

CVSS 3.1 Score 9.4 of 10 (high)

Details

Published Feb 12, 2025
CWE ID 290

Summary

CVE-2025-25182 is a vulnerability affecting the Stroom data processing platform, impacting versions 7.2-beta.53 and earlier, as well as versions 7.3-beta.22, 7.4.4, and 7.5-beta.2. When configured with Application Load Balancer (ALB) and installed with application accessibility outside of the ALB itself, this issue enables authentication bypass. Potentially, it may also lead to server-side request forgery, escalating to code execution or further privileges. This vulnerability is resolved in versions 7.2.24, 7.3-beta.22, 7.4.4, and 7.5-beta.2.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share