CVE-2025-8708

A vulnerability was found in Antabot White-Jotter 0.22. It has been declared as critical. This vulnerability affects the function CookieRememberMeManager of the file ShiroConfiguration.java of the component com.gm.wj.config.ShiroConfiguration. The manipulation with the input EVANNIGHTLY_WAOU leads to deserialization. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:antabot:white-jotter:0.2.2:*:*:*:*:*:*:*

History

21 Aug 2025, 20:54

Type Values Removed Values Added
CPE cpe:2.3:a:antabot:white-jotter:0.2.2:*:*:*:*:*:*:*
First Time Antabot
Antabot white-jotter
References () https://github.com/Antabot/White-Jotter/issues/161 - () https://github.com/Antabot/White-Jotter/issues/161 - Exploit, Issue Tracking
References () https://github.com/Antabot/White-Jotter/issues/161#issue-3254420874 - () https://github.com/Antabot/White-Jotter/issues/161#issue-3254420874 - Exploit, Issue Tracking
References () https://vuldb.com/?ctiid.319138 - () https://vuldb.com/?ctiid.319138 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.319138 - () https://vuldb.com/?id.319138 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.621105 - () https://vuldb.com/?submit.621105 - Third Party Advisory, VDB Entry

08 Aug 2025, 15:15

Type Values Removed Values Added
References () https://github.com/Antabot/White-Jotter/issues/161#issue-3254420874 - () https://github.com/Antabot/White-Jotter/issues/161#issue-3254420874 -
Summary
  • (es) Se encontró una vulnerabilidad en Antabot White-Jotter 0.22. Se ha declarado crítica. Esta vulnerabilidad afecta a la función CookieRememberMeManager del archivo ShiroConfiguration.java del componente com.gm.wj.config.ShiroConfiguration. La manipulación de la entrada EVANNIGHTLY_WAOU provoca la deserialización. El ataque puede ejecutarse en remoto. Es un ataque de complejidad bastante alta. Parece difícil de explotar. Se ha hecho público el exploit y puede que sea utilizado.

08 Aug 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-08 03:15

Updated : 2025-08-21 20:54


NVD link : CVE-2025-8708

Mitre link : CVE-2025-8708

CVE.ORG link : CVE-2025-8708


JSON object : View

Products Affected

antabot

  • white-jotter
CWE
CWE-20

Improper Input Validation

CWE-502

Deserialization of Untrusted Data