GHSL-2024-200: _GHSL-2024-201: Zero click RCE in Uptrain - CVE-2025-27771, CVE-2025-27772
The Uptrain dashboard lacks significant authentication, has an open CORS policy, and is vulnerable to a remote code execution vulnerability. Combining these primitives, an attacker can get zero click remote code execution in the context of the Uptrain host by directing an Uptrain user to a specially crafted website.
Affected Software
Event History
Frequently Asked Questions
What is the severity of GHSL-2024-200?
The severity of GHSL-2024-200 is rated at 88, indicating a high risk of exploitation.
How do I fix GHSL-2024-200?
To fix GHSL-2024-200, apply the latest security patches provided by Uptrain and ensure proper authentication and CORS policies are implemented.
What systems are affected by GHSL-2024-200?
GHSL-2024-200 affects systems using the Uptrain dashboard that lack sufficient authentication and have an open CORS policy.
What is the impact of GHSL-2024-200?
The impact of GHSL-2024-200 allows an attacker to achieve zero click remote code execution on the Uptrain host.
Is there a workaround for GHSL-2024-200?
A recommended workaround for GHSL-2024-200 is to restrict the CORS policy and implement stronger authentication measures until a patch can be applied.