Launch Week Day 1: Announcing Security Design Review
CRITICAL 9.0 RubyGems

Oxidized Web RANCID migration page allows unauthenticated user to gain control over Linux user account

GHSA-jx6p-9c26-g373 · CVE-2025-27590

Published · Modified

Description

In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain control over the Linux user account that is running oxidized-web.

Ready to move

Start Securing

Free, no credit card | First findings in minutes