CVE-2025-23212

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The external storage feature allows any user to enumerate the name and content of files on the server. This vulnerability is fixed in 1.5.28.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tandoor:recipes:*:*:*:*:*:*:*:*

History

08 May 2025, 18:45

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:tandoor:recipes:*:*:*:*:*:*:*:*
First Time Tandoor
Tandoor recipes
CWE NVD-CWE-noinfo
References () https://github.com/TandoorRecipes/recipes/commit/36e83a9d0108ac56b9538b45ead57efc8b97c5ff - () https://github.com/TandoorRecipes/recipes/commit/36e83a9d0108ac56b9538b45ead57efc8b97c5ff - Patch
References () https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-jrgj-35jx-2qq7 - () https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-jrgj-35jx-2qq7 - Exploit, Vendor Advisory

28 Jan 2025, 17:15

Type Values Removed Values Added
CWE CWE-200

28 Jan 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-28 16:15

Updated : 2025-05-08 18:45


NVD link : CVE-2025-23212

Mitre link : CVE-2025-23212


JSON object : View

Products Affected

tandoor

  • recipes