PT-2025-32465 · Unknown · Litmuschaos
Maique
·
Published
2025-08-10
·
Updated
2025-08-13
·
CVE-2025-8791
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
LitmusChaos versions prior to 3.19.0
Description:
A critical issue exists in LitmusChaos related to improper authorization. The vulnerability stems from the manipulation of the
role argument during the processing of the /auth/list projects API endpoint, potentially allowing for remote attacks. The exploit for this issue has been publicly disclosed. The vendor was informed of the vulnerability but did not respond.Recommendations:
Update to a version beyond 3.19.0.
As a temporary workaround, restrict access to the
/auth/list projects API endpoint.Exploit
Fix
Improper Authorization
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Litmuschaos