CVE-2025-24502

CWE-3843 documents3 sources
Severity
5.3MEDIUM
EPSS
0.1%
top 82.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 30

Description

An improper session validation allows an unauthenticated attacker to cause certain request notifications to be executed in the context of an incorrect user by spoofing the client IP address.

CVSS vector

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Packages1 packages

🔴Vulnerability Details

2
CVEList
CVE-2025-24502: An improper session validation allows an unauthenticated attacker to cause certain request notifications to be executed in the context of an incorrect2025-01-30
GHSA
GHSA-h46m-532h-mwqc: An improper session validation allows an unauthenticated attacker to cause certain request notifications to be executed in the context of an incorrect2025-01-30
CVE-2025-24502 (MEDIUM CVSS 5.3) | An improper session validation allo | cvebase.io