CVE-2025-13948

MEDIUM

opsre go-ldap-admin <20251011 - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability was determined in opsre go-ldap-admin up to 20251011. This issue affects some unknown processing of the file docs/docker-compose/docker-compose.yaml of the component JWT Handler. Executing manipulation of the argument secret key can lead to use of hard-coded cryptographic key . The attack can be launched remotely. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit has been publicly disclosed and may be utilized.

References (4)

Core 4
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.334163
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.334163
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.692213

Scores

CVSS v3 5.6
EPSS 0.0025
EPSS Percentile 16.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-320 CWE-321
Status published
Products (1)
opsre/go-ldap-admin 20251011
Published Dec 03, 2025
Tracked Since Feb 18, 2026