← Zuruck zu CVEs
CVE-2025-23211
CRITICAL9.9
Beschreibung
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. A Jinja2 SSTI vulnerability allows any user to execute commands on the server. In the case of the provided Docker Compose file as root. This vulnerability is fixed in 1.5.24.
CVE Details
CVSS v3.1 Bewertung9.9
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienLOW
BenutzerinteraktionNONE
Veroffentlicht1/28/2025
Zuletzt geandert5/8/2025
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
tandoor:recipes
Schwachen (CWE)
CWE-1336CWE-94
Referenzen
https://github.com/TandoorRecipes/recipes/blob/4f9bff20c858180d0f7376de443a9fe4c123a50c/cookbook/helper/template_helper.py#L95(security-advisories@github.com)
https://github.com/TandoorRecipes/recipes/commit/e6087d5129cc9d0c24278948872377e66c2a2c20(security-advisories@github.com)
https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-r6rj-h75w-vj8v(security-advisories@github.com)
https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-r6rj-h75w-vj8v(134c704f-9b21-4f2e-91b3-4a467353bcc0)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.