/user/namespace/{namespace}/details API allows a user to edit all
namespace details, even if the user is not a namespace Owner or
Contributor. The details include: name, description, website, support
link and social media links. The same issues existed in
/user/namespace/{namespace}/details/logo and allowed a user to change
the logo.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-5091 | In OpenVSX version v0.9.0 to v0.20.0, the /user/namespace/{namespace}/details API allows a user to edit all namespace details, even if the user is not a namespace Owner or Contributor. The details include: name, description, website, support link and social media links. The same issues existed in /user/namespace/{namespace}/details/logo and allowed a user to change the logo. |
Thu, 31 Jul 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eclipse
Eclipse open Vsx |
|
| CPEs | cpe:2.3:a:eclipse:open_vsx:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Eclipse
Eclipse open Vsx |
|
| Metrics |
cvssV3_1
|
Wed, 19 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 19 Feb 2025 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In OpenVSX version v0.9.0 to v0.20.0, the /user/namespace/{namespace}/details API allows a user to edit all namespace details, even if the user is not a namespace Owner or Contributor. The details include: name, description, website, support link and social media links. The same issues existed in /user/namespace/{namespace}/details/logo and allowed a user to change the logo. | |
| Title | Improper Authorization in /user/namespace/{namespace}/details | |
| Weaknesses | CWE-283 CWE-285 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2025-02-19T19:36:50.732Z
Reserved: 2025-02-03T22:18:13.955Z
Link: CVE-2025-1007
Updated: 2025-02-19T19:36:44.155Z
Status : Analyzed
Published: 2025-02-19T09:15:10.117
Modified: 2025-07-31T12:44:45.817
Link: CVE-2025-1007
No data.
OpenCVE Enrichment
No data.
EUVD