8.2
CVE-2025-65781
- EPSS 0.33%
- Veröffentlicht 15.12.2025 00:00:00
- Zuletzt bearbeitet 18.12.2025 01:35:29
- CVE-Watchlists
- Unerledigt
An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upload API treats the Authorization bearer value as a userId and enters a non-terminating body-handling branch for any non-empty bearer token, enabling trivial application-layer DoS and latent identity-spoofing.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wekan Project ≫ Wekan Version < 8.16
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.33% | 0.262 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.2 | 3.9 | 4.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
|
| CISA-ADP | 8.2 | 3.9 | 4.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
https://github.com/wekan/wekan
https://wekan.fi/hall-of-fame/spacebleed/
https://github.com/wekan/wekan/blob/main/CHANGELOG.md#v816-2025-11-02-wekan--release
https://github.com/wekan/wekan/commit/ccd90343394f433b287733ad0a33c08e0a71f53c