CVE-2025-27581

NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 allows users who lack the InET role to access the InET module via direct requests to known endpoints.
Configurations

No configuration.

History

29 Apr 2025, 13:52

Type Values Removed Values Added
Summary
  • (es) NIH BRICS (también conocido como Biomedical Research Informatics Computing System) hasta la versión 14.0.0-67 permite a los usuarios que no tienen el rol InET acceder al módulo InET mediante solicitudes directas a endpoints conocidos.

24 Apr 2025, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-24 00:15

Updated : 2025-04-29 13:52


NVD link : CVE-2025-27581

Mitre link : CVE-2025-27581

CVE.ORG link : CVE-2025-27581


JSON object : View

Products Affected

No product.

CWE
CWE-425

Direct Request ('Forced Browsing')