Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27774 | An insufficiently secured internal function allows session generation for arbitrary users. The decodeParam function checks the JWT but does not verify which signing algorithm was used. As a result, an attacker can use the "ex:action" parameter in the VerifyUserByThrustedService function to generate a session for any user. |
| Link | Providers |
|---|---|
| https://cert.pl/en/posts/2025/08/CVE-2025-2313/ |
|
Wed, 27 Aug 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cgm
Cgm clininet |
|
| Vendors & Products |
Cgm
Cgm clininet |
Wed, 27 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 Aug 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An insufficiently secured internal function allows session generation for arbitrary users. The decodeParam function checks the JWT but does not verify which signing algorithm was used. As a result, an attacker can use the "ex:action" parameter in the VerifyUserByThrustedService function to generate a session for any user. | |
| Title | Possibility to generate a session for any user via the "ex:action" parameter after obtaining access to the JWT key | |
| Weaknesses | CWE-347 CWE-912 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2025-08-27T13:25:58.795Z
Reserved: 2025-03-14T14:55:39.571Z
Link: CVE-2025-30064
Updated: 2025-08-27T13:25:53.638Z
Status : Deferred
Published: 2025-08-27T11:15:41.627
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-30064
No data.
OpenCVE Enrichment
Updated: 2025-08-27T21:57:39Z
EUVD