PT-2025-48411 · Orionsec · Orion-Ops
Sh7Err03
·
Published
2025-12-01
·
Updated
2025-12-01
·
CVE-2025-13807
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
orionsec orion-ops versions up to 5925824997a3109651bbde07460958a7be249ed1
Description
A flaw exists in orionsec orion-ops that leads to improper authorization. This issue is located within the
MachineKeyController function in the MachineKeyController.java file of the API component. The issue can be exploited remotely. The exploit is publicly available. The vendor was notified but did not respond.Recommendations
Versions up to 5925824997a3109651bbde07460958a7be249ed1 should be updated. As a temporary workaround, consider restricting access to the
MachineKeyController function until a patch is available.Exploit
Fix
Improper Authorization
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Orion-Ops