CNNVD-202512-3133 Information

CNNVD ID

CNNVD-202512-3133

CVE-2025-68435

  • CNNVD Published: 2025-12-17

Description (Chinese)

Zerobyte是Nico个人开发者的一个主机自动备份软件。 Zerobyte 0.18.5之前版本和0.19.0之前版本存在安全漏洞,该漏洞源于身份验证中间件未正确应用于API端点,可能导致身份验证绕过。

Description (English)

Zerobyte is an automated mainframe backup software for Nico personal developers. There was a security loophole in the pre-Zerobyte 0.18.5 and pre-0.19.0 versions, which stemmed from the incorrect application of the authentication intermediate to the API endpoint, which could result in the identification being bypassed.

Hazard Level

Low

Vulnerability Type

其他

Affected Vendor

个人开发者

Published

2025-12-17

Last Modified

2026-02-24

References

https://github.com/nicotsx/zerobyte/security/advisories/GHSA-x539-c98q-38gv https://github.com/nicotsx/zerobyte/issues/161 https://github.com/nicotsx/zerobyte/commit/13e080a18967705bd2b4e110e5f7693fdca1c692 https://access.redhat.com/security/cve/cve-2025-68435

Patch

https://github.com/nicotsx/zerobyte/releases

Share on: