PT-2025-32465 · Unknown · Litmuschaos

Maique

·

Published

2025-08-10

·

Updated

2025-08-13

·

CVE-2025-8791

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: LitmusChaos versions prior to 3.19.0
Description: A critical issue exists in LitmusChaos related to improper authorization. The vulnerability stems from the manipulation of the role argument during the processing of the /auth/list projects API endpoint, potentially allowing for remote attacks. The exploit for this issue has been publicly disclosed. The vendor was informed of the vulnerability but did not respond.
Recommendations: Update to a version beyond 3.19.0. As a temporary workaround, restrict access to the /auth/list projects API endpoint.

Exploit

Fix

Improper Authorization

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2025-8791

Affected Products

Litmuschaos