CWE-552: Files or Directories Accessible to External Parties vulnerability over https exists that could leak information and potential privilege escalation following man in the middle attack.
History

Wed, 09 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Apr 2025 10:30:00 +0000

Type Values Removed Values Added
Description CWE-552: Files or Directories Accessible to External Parties vulnerability over https exists that could leak information and potential privilege escalation following man in the middle attack.
Weaknesses CWE-552
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published: 2025-04-09T10:12:33.428Z

Updated: 2025-04-09T14:05:05.060Z

Reserved: 2025-03-11T16:52:36.636Z

Link: CVE-2025-2222

cve-icon Vulnrichment

Updated: 2025-04-09T14:04:53.993Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-09T11:15:42.063

Modified: 2025-04-09T20:02:41.860

Link: CVE-2025-2222

cve-icon Redhat

No data.