Beveiligingsadvies

CVE-2025-62166

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-03-09 19:35:37
Laatst bijgewerkt 2026-03-09 20:44:25
Toegewezen door GitHub_M
CVSS-score 7.5
Status PUBLISHED

Beschrijving

FreshRSS is a free, self-hostable RSS aggregator. Prior 1.28.0, a bug in the auth logic related to master authentication tokens, this restriction is bypassed. Usually only the default user's feed should be viewable if anonymous viewing is enabled, and feeds of other users should be private. This vulnerability is fixed in 1.28.0.