CNNVD-202510-2836 Information
CNNVD ID
CNNVD-202510-2836
Related CVE
- CNNVD Published: 2025-10-22
Description (Chinese)
MeterSphere是MeterSphere开源的一站式开源持续测试平台。 MeterSphere 2.10.25-lts之前版本存在信息泄露漏洞,该漏洞源于逻辑缺陷,可能导致任意用户信息泄露和未经验证的攻击者登录系统。
Description (English)
MeterSphere is a one-stop open source continuous testing platform for the MeterSphere Open Source. The previous version of MeterSphere 2.10.25-lts had a leaking loophole, which stemmed from a logical flaw that could lead to the disclosure of any user information and unverified aggressor log-in systems.
Hazard Level
High
Vulnerability Type
信息泄露
Affected Vendor
MeterSphere
Published
2025-10-22
Last Modified
2026-02-24
References
https://github.com/metersphere/metersphere/releases/tag/v2.10.25-lts https://github.com/metersphere/metersphere/security/advisories/GHSA-vj5x-7374-rf96 https://github.com/metersphere/metersphere/commit/b984fe74e84711ff326b0a348807c31fadf134af https://access.redhat.com/security/cve/cve-2025-62604
Patch
https://github.com/metersphere/metersphere/releases
Share on: