A vulnerability has been found in LitmusChaos Litmus up to 3.19.0 and classified as problematic. This vulnerability affects unknown code of the file /auth/delete_project/ of the component Delete Request Handler. The manipulation of the argument projectID leads to missing authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Affected Vendors & Products
References
History
Tue, 12 Aug 2025 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Litmus Project
Litmus Project litmus |
|
Vendors & Products |
Litmus Project
Litmus Project litmus |
Sun, 10 Aug 2025 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability has been found in LitmusChaos Litmus up to 3.19.0 and classified as problematic. This vulnerability affects unknown code of the file /auth/delete_project/ of the component Delete Request Handler. The manipulation of the argument projectID leads to missing authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | LitmusChaos Litmus Delete Request delete_project authorization | |
Weaknesses | CWE-862 CWE-863 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-08-10T06:02:06.440Z
Updated: 2025-08-10T06:02:06.440Z
Reserved: 2025-08-09T05:34:15.676Z
Link: CVE-2025-8796

No data.

Status : Awaiting Analysis
Published: 2025-08-10T06:15:26.920
Modified: 2025-08-11T18:32:48.867
Link: CVE-2025-8796

No data.