Beveiligingsadvies

CVE-2025-60949

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-03-23 21:00:55
Laatst bijgewerkt 2026-03-25 14:50:13
Toegewezen door cisa-cg
CVSS-score 9.3
Status PUBLISHED

Beschrijving

Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. A remote, unauthenticated attacker could send requests to configuration files and obtain leaked secrets. Fixed in 8.1.0 alpha.