CVE-2025-57403

🟡 Monitoruj

Wykorzystanie przepełnienia bufora w Cola Dnslog umożliwia ujawnienie wrażliwych informacji.

CVSS
7.5
EPSS
1.0%
Exploit
poc
Vendor
abelche
Opis źródłowy (NVD)

Cola Dnslog v1.3.2 is vulnerable to Directory Traversal. When a DNS query for a TXT record is processed, the application concatenates the requested URL (or a portion of it) directly with a base path using os.path.join. This bypass allows directory traversal or absolute path injection, leading to the potential exposure of sensitive information.

exploit path-traversal Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)1.0%
Opublikowano (NVD)2025-12-26 16:15:43 UTC
Ostatnia modyfikacja (NVD)2026-10-05 18:10:00 UTC
Referencje