CVE-2025-27137
CVSS 3.1 Score 4.4 of 10 (medium)
Details
Summary
CVE-2025-27137 is a vulnerability affecting Dependency-Track, a component analysis platform. Prior to version 4.12.6, users with the `SYSTEM_CONFIGURATION` permission were able to abuse the Pebble template engine's `include` tag in notification templates. This tag allowed the inclusion of arbitrary local files during evaluation, potentially leading to sensitive information leaks, such as `/etc/passwd` or `/proc/1/environ`. The vulnerability has been addressed in Dependency-Track 4.12.6, where the use of the `include` tag is no longer permitted, causing template evaluation to fail. It is recommended to avoid assigning the `SYSTEM_CONFIGURATION` permission to untrusted users, as it poses a security risk in itself and should be limited to the `Administrators` team.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.