CVE-2025-54955

CVE Details

Basic Information

Title CVE-2025-54955
Type cve
Published 2025-08-02T00:00:00.000Z
Modified 2025-08-02T23:39:43.929Z

Product Information

Vendor OpenNebula
Product OpenNebula
Version Enterprise Edition

CVSS Information

Base Score 8.1 (HIGH)
Attack Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

  • OpenNebula OpenNebula Enterprise Edition
  • OpenNebula OpenNebula Community Edition

Additional Information

CWE List CWE-362
Source mitre

Description

OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition (EE) before 6.10.3 have a critical FireEdge race condition that can lead to full account takeover. By exploiting this, an unauthenticated attacker can obtain a valid JSON Web Token (JWT) belonging to a legitimate user without knowledge of their credentials.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.