PT-2025-10972 · Opal · Opal

Parnuski

·

Published

2025-03-11

·

Updated

2025-03-12

·

CVE-2025-27101

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Opal versions prior to 5.1.1
Description: The issue affects Opal, the core database application for biobanks or epidemiological studies. When copying any parent directory to a folder in the "/temp/" directory, all files in that parent directory are copied, including files that the user should not have access to. This means any user can exploit this to reveal all files in the Opal filesystem. Low-privilege users, such as DataShield users, can retrieve the files of other users.
Recommendations: For versions prior to 5.1.1, update to version 5.1.1, which includes a patch for this issue. As a temporary workaround, consider restricting access to the "/temp/" directory to minimize the risk of exploitation. Avoid using the /temp/ directory for sensitive operations until the issue is resolved.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-62432
CVE-2025-27101
GHSA-RXMX-GQJJ-VHV8

Affected Products

Opal