CNNVD-202510-3811 Information
Oct 28, 2025
cve
CNNVD ID
CNNVD-202510-3811
Related CVE
- CNNVD Published: 2025-10-28
Description (Chinese)
IPFire是IPFire组织的一种开源 Linux 发行版。主要用作路由器和防火墙。 IPFire 2.29之前版本存在安全漏洞,该漏洞源于未对TLS_HOSTNAME参数进行适当清理或编码,可能导致存储型跨站脚本攻击。
Description (English)
IPFire is an open source for the organization Linux. Mainly used as routers and firewalls. Prior to IPFire 2.29, there was a security loophole, which arose from the failure to properly clean or encode TLS HOSTNAME parameters, which could lead to a storage-type cross-site script attack.
Hazard Level
High
Vulnerability Type
其他
Affected Vendor
IPFire
Published
2025-10-28
Last Modified
2026-02-24
References
https://bugzilla.ipfire.org/show_bug.cgi?id=13892 https://www.ipfire.org/blog/ipfire-2-29-core-update-198-released https://www.vulncheck.com/advisories/ipfire-stored-xss-via-dns-settings-dns-cgi https://access.redhat.com/security/cve/cve-2025-34317
Patch
https://www.ipfire.org/downloads/ipfire-2.29-core198
Share on: