GHSL-2024-201: GHSL-2024-200_GHSL-2024-201: Zero click RCE in Uptrain - CVE-2025-27771, CVE-2025-27772
The Uptrain dashboard lacks significant authentication, has an open CORS policy, and is vulnerable to a remote code execution vulnerability. Combining these primitives, an attacker can get zero click remote code execution in the context of the Uptrain host by directing an Uptrain user to a specially crafted website.
Affected Software
Event History
Frequently Asked Questions
What is the severity of GHSL-2024-201?
GHSL-2024-201 has a risk rating of 89, indicating a high severity level due to its zero click remote code execution vulnerability.
How do I fix GHSL-2024-201?
To fix GHSL-2024-201, ensure that proper authentication mechanisms are implemented and review CORS policy settings to restrict unauthorized access.
What impact does GHSL-2024-201 have on the Uptrain dashboard?
The impact of GHSL-2024-201 includes the potential for remote code execution by an attacker without any user interaction.
Is GHSL-2024-201 applicable to all versions of Uptrain?
GHSL-2024-201 specifically affects the Uptrain dashboard, and it is advised to check for updates or patches released by Uptrain.
Who should be concerned about the GHSL-2024-201 vulnerability?
Organizations using the Uptrain dashboard should be concerned about GHSL-2024-201 as it poses significant security risks to their systems.