CVE-2025-7552

medium

Description

A vulnerability was found in Dromara Northstar up to 7.3.5. It has been rated as critical. Affected by this issue is the function preHandle of the file northstar-main/src/main/java/org/dromara/northstar/web/interceptor/AuthorizationInterceptor.java of the component Path Handler. The manipulation of the argument Request leads to improper access controls. The attack may be launched remotely. Upgrading to version 7.3.6 is able to address this issue. The patch is identified as 8d521bbf531de59b09b8629a9cbf667870ad2541. It is recommended to upgrade the affected component.

References

https://vuldb.com/?id.316250

https://vuldb.com/?ctiid.316250

https://gitee.com/dromara/northstar/releases/tag/v7.3.6

https://gitee.com/dromara/northstar/issues/ICCQ4E#note_42855013_link

https://gitee.com/dromara/northstar/issues/ICCQ4E

https://gitee.com/dromara/northstar/commit/8d521bbf531de59b09b8629a9cbf667870ad2541

Details

Source: Mitre, NVD

Published: 2025-07-14

Updated: 2025-07-15

Risk Information

CVSS v2

Base Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 6.3

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Severity: Medium

CVSS v4

Base Score: 5.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Severity: Medium

EPSS

EPSS: 0.00043