Aller au contenu

Fiche vulnérabilité

CVE-2025-57817 : faille élevée ethyca fides (CVSS 7.2)

Description

Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the OAuth client creation and update endpoints of the Fides Webserver API do not properly authorize scope assignment. This allows highly privileged users with `client:create` or `client:update` permissions to escalate their privileges to owner-level. Version 2.69.1 fixes the issue. No known workarounds are available.

En bref

Sévérité
Élevée (CVSS 7.2)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
8 sept. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • ethyca fides

Références

Rechercher une autre vulnérabilité dans la base CVE