Record summary

CVE-2023-25573 has a selected CVSS score of 8.6 (high); EIP currently links 1 Nuclei template.

Description

metersphere is an open source continuous testing platform. In affected versions an improper access control vulnerability exists in `/api/jmeter/download/files`, which allows any user to download any file without authentication. This issue may expose all files available to the running process. This issue has been addressed in version 1.20.20 lts and 2.7.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 4, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 25, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List, VulnCheck< 1.20.20 ltsaffected
>= 2.0.0, < 2.7.1affected

Nuclei templates

1
ProjectDiscoveryHIGHMetersphere - Arbitrary File ReadCVSS 7.5

Metersphere is an open source continuous testing platform. In affected versions an improper access control vulnerability exists in `/api/jmeter/download/files`, which allows any user to download any file without authentication. This issue may expose all files available to the running process. This issue has been addressed in version 1.20.20 lts and 2.7.1

Impact

This vulnerability can lead to unauthorized access to sensitive information, such as configuration files, credentials, and other sensitive data.

Remediation

Users are advised to upgrade. There are no known workarounds for this vulnerability.

WeaknessesCWE-862
AuthorsDhiyaneshDK
Template tagscvecve2023meterspherelfivkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:metersphere:metersphere:*:*:*:*:*:*:*:*
Shodan: http.html:"metersphere"
FOFA: body="Metersphere"
FOFA: body="metersphere"
FOFA: title="metersphere"

Source: ProjectDiscovery

References

1