CVE-2025-27590
CRITICALOxidized Web < 0.15.0 - Path Traversal
Title source: ruleDescription
In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain control over the Linux user account that is running oxidized-web.
Exploits (1)
Scores
CVSS v3
9.0
EPSS
0.1340
EPSS Percentile
94.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Details
CWE
CWE-22
Status
published
Products (2)
oxidized_web_project/oxidized_web
< 0.15.0
rubygems/oxidized-web
0 - 0.15.0RubyGems
Published
Mar 03, 2025
Tracked Since
Feb 18, 2026