Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The external storage feature allows any user to enumerate the name and content of files on the server. This vulnerability is fixed in 1.5.28.
History

Tue, 28 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jan 2025 15:45:00 +0000

Type Values Removed Values Added
Description Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The external storage feature allows any user to enumerate the name and content of files on the server. This vulnerability is fixed in 1.5.28.
Title Tandoor Recipes - Local file disclosure - Users can read the content of any file on the server
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-01-28T15:29:07.948Z

Updated: 2025-01-28T16:10:06.786Z

Reserved: 2025-01-13T17:15:41.051Z

Link: CVE-2025-23212

cve-icon Vulnrichment

Updated: 2025-01-28T16:09:44.630Z

cve-icon NVD

Status : Received

Published: 2025-01-28T16:15:41.080

Modified: 2025-01-28T17:15:26.273

Link: CVE-2025-23212

cve-icon Redhat

No data.