PT-2025-52456 · Unknown · Turms Server
Xzzz111
·
Published
2025-12-19
·
Updated
2026-01-02
·
CVE-2025-66910
CVSS v3.1
6.0
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Turms Server versions prior to 0.10.0-SNAPSHOT
Description
The software stores administrator passwords in plaintext within memory, specifically in the
rawPassword field of AdminInfo objects, to improve authentication speed. This bypasses the bcrypt protection normally used. An attacker with local system access could obtain these passwords through methods like memory dumps or heap analysis.Recommendations
Update to a version newer than 0.10.0-SNAPSHOT.
Exploit
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Turms Server