PT-2025-7790 · Unknown · Dependency-Track

Jonathan Leitschuh

·

Published

2025-02-24

·

Updated

2025-02-28

·

CVE-2025-27137

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Dependency-Track versions prior to 4.12.6
Description The issue allows users with the SYSTEM CONFIGURATION permission to abuse the include tag in notification templates, potentially leaking sensitive local files, such as /etc/passwd or /proc/1/environ, by including them in notification templates and sending notifications to a controlled destination.
Recommendations For versions prior to 4.12.6, avoid assigning the SYSTEM CONFIGURATION permission to untrusted users, as this permission is a security risk if granted to non-administrative users or teams. Update to version 4.12.6 or later, where the include tag can no longer be used and its usage will cause template evaluation to fail.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-27137
GHSA-9582-88HR-54W3
GHSA-P75G-CXFJ-7WRX

Affected Products

Dependency-Track