Dromara Northstar Path AuthorizationInterceptor.java preHandle access control

CVE Details

Basic Information

Title Dromara Northstar Path AuthorizationInterceptor.java preHandle access control
Type cve
Published 2025-07-13T23:32:15.706Z
Modified 2025-07-13T23:32:15.706Z

Product Information

Vendor Dromara
Product Northstar
Version 7.3.0

CVSS Information

Base Score 5.3 (MEDIUM)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X

Affected Products

  • Dromara Northstar 7.3.0
  • Dromara Northstar 7.3.1
  • Dromara Northstar 7.3.2
  • Dromara Northstar 7.3.3
  • Dromara Northstar 7.3.4
  • Dromara Northstar 7.3.5

Additional Information

CWE List CWE-284, CWE-266
Source VulDB

Description

A vulnerability was found in Dromara Northstar up to 7.3.5. It has been rated as critical. Affected by this issue is the function preHandle of the file northstar-main/src/main/java/org/dromara/northstar/web/interceptor/AuthorizationInterceptor.java of the component Path Handler. The manipulation of the argument Request leads to improper access controls. The attack may be launched remotely. Upgrading to version 7.3.6 is able to address this issue. The patch is identified as 8d521bbf531de59b09b8629a9cbf667870ad2541. It is recommended to upgrade the affected component.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.