CVE-2025-13948

MEDIUM

opsre go-ldap-admin <20251011 - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability was determined in opsre go-ldap-admin up to 20251011. This issue affects some unknown processing of the file docs/docker-compose/docker-compose.yaml of the component JWT Handler. Executing manipulation of the argument secret key can lead to use of hard-coded cryptographic key . The attack can be launched remotely. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit has been publicly disclosed and may be utilized.

Scores

CVSS v3 5.6
EPSS 0.0003
EPSS Percentile 10.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-320 CWE-321
Status published
Products (1)
opsre/go-ldap-admin 20251011
Published Dec 03, 2025
Tracked Since Feb 18, 2026