CVE 8.1 HIGH

CVE-2025-54955_CVE-2025-54955

8.1 / 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition (EE) before 6.10.3 have a critical FireEdge race condition that can lead to full account takeover. By exploiting this, an unauthenticated attacker can obtain a valid JSON Web Token (JWT) belonging to a legitimate user without knowledge of their credentials.

Basic Information

ID CVE-2025-54955
Source mitre
Published Aug 2, 2025 at 00:00
Modified Aug 4, 2025 at 15:20

Affected Product

Vendor OpenNebula
Product OpenNebula
Version Enterprise Edition
Affected Versions OpenNebula OpenNebula Enterprise Edition
OpenNebula OpenNebula Community Edition

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.