CNNVD-202510-2836 Information

CNNVD ID

CNNVD-202510-2836

CVE-2025-62604

  • CNNVD Published: 2025-10-22

Description (Chinese)

MeterSphere是MeterSphere开源的一站式开源持续测试平台。 MeterSphere 2.10.25-lts之前版本存在信息泄露漏洞,该漏洞源于逻辑缺陷,可能导致任意用户信息泄露和未经验证的攻击者登录系统。

Description (English)

MeterSphere is a one-stop open source continuous testing platform for the MeterSphere Open Source. The previous version of MeterSphere 2.10.25-lts had a leaking loophole, which stemmed from a logical flaw that could lead to the disclosure of any user information and unverified aggressor log-in systems.

Hazard Level

High

Vulnerability Type

信息泄露

Affected Vendor

MeterSphere

Published

2025-10-22

Last Modified

2026-02-24

References

https://github.com/metersphere/metersphere/releases/tag/v2.10.25-lts https://github.com/metersphere/metersphere/security/advisories/GHSA-vj5x-7374-rf96 https://github.com/metersphere/metersphere/commit/b984fe74e84711ff326b0a348807c31fadf134af https://access.redhat.com/security/cve/cve-2025-62604

Patch

https://github.com/metersphere/metersphere/releases

Share on: