PT-2025-10972 · Opal · Opal
Parnuski
·
Published
2025-03-11
·
Updated
2025-03-12
·
CVE-2025-27101
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
Opal versions prior to 5.1.1
Description:
The issue affects Opal, the core database application for biobanks or epidemiological studies. When copying any parent directory to a folder in the "/temp/" directory, all files in that parent directory are copied, including files that the user should not have access to. This means any user can exploit this to reveal all files in the Opal filesystem. Low-privilege users, such as DataShield users, can retrieve the files of other users.
Recommendations:
For versions prior to 5.1.1, update to version 5.1.1, which includes a patch for this issue. As a temporary workaround, consider restricting access to the "/temp/" directory to minimize the risk of exploitation. Avoid using the
/temp/ directory for sensitive operations until the issue is resolved.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opal