Skip to main content

Vendor/product archive

fedorarepository / fcrepo CVEs

Beta · best-effort

2 CVEs tagged to fedorarepository / fcrepo0 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2025-23012

Published Jan 23, 2025

Fedora Repository 3.8.x includes a service account (fedoraIntCallUser) with default credentials and privileges to read read local files by manipulating datastreams. Fedora Reposit…

CVSS 8.7 · High
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2025-23011

Published Jan 23, 2025

Fedora Repository 3.8.1 allows path traversal when extracting uploaded archives ("Zip Slip"). A remote, authenticated attacker can upload a specially crafted archive that will ext…

CVSS 8.7 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1