CVE-2025-66422
⚪ Do wiadomości
Luka w Tryton umożliwia zdalnym atakującym uzyskanie wrażliwych informacji o konfiguracji serwera.
CVSS
4.3
EPSS
0.3%
Exploit
poc
Vendor
tryton
Opis źródłowy (NVD)
Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.
exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 4.3 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2025-11-30 03:15:47 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-07 20:10:01 UTC |
Referencje
- https://discuss.tryton.org/t/security-release-for-issue-14354/8950 ([email protected]) [Vendor Advisory]
- https://foss.heptapod.net/tryton/tryton/-/issues/14354 ([email protected]) [Exploit, Issue Tracking]