Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-3073 | Fedora Repository 3.8.x includes a service account (fedoraIntCallUser) with default credentials and privileges to read read local files by manipulating datastreams. Fedora Repository 3.8.1 was released on 2015-06-11 and is no longer maintained. Migrate to a currently supported version (6.5.1 as of 2025-01-23). |
Tue, 07 Oct 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fedorarepository
Fedorarepository fcrepo |
|
| CPEs | cpe:2.3:a:fedorarepository:fcrepo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fedorarepository
Fedorarepository fcrepo |
Wed, 12 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 23 Jan 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Fedora Repository 3.8.x includes a service account (fedoraIntCallUser) with default credentials and privileges to read read local files by manipulating datastreams. Fedora Repository 3.8.1 was released on 2015-06-11 and is no longer maintained. Migrate to a currently supported version (6.5.1 as of 2025-01-23). | |
| Title | Fedora Repository fedoraIntCallUser default credentials | |
| Weaknesses | CWE-1392 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2025-02-12T20:41:30.107Z
Reserved: 2025-01-09T16:12:49.111Z
Link: CVE-2025-23012
Updated: 2025-02-12T20:35:55.317Z
Status : Analyzed
Published: 2025-01-23T21:15:15.173
Modified: 2025-10-07T16:47:21.827
Link: CVE-2025-23012
No data.
OpenCVE Enrichment
No data.
EUVD