CVE-2025-23212

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The external storage feature allows any user to enumerate the name and content of files on the server. This vulnerability is fixed in 1.5.28.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tandoor:recipes:*:*:*:*:*:*:*:*

History

08 May 2025, 18:45

Type Values Removed Values Added
Summary
  • (es) Tandoor Recipes es una aplicación para gestionar recetas, planificar comidas y crear listas de compras. La función de almacenamiento externo permite a cualquier usuario enumerar el nombre y el contenido de los archivos en el servidor. Esta vulnerabilidad se solucionó en la versión 1.5.28.
CWE NVD-CWE-noinfo
References () https://github.com/TandoorRecipes/recipes/commit/36e83a9d0108ac56b9538b45ead57efc8b97c5ff - () https://github.com/TandoorRecipes/recipes/commit/36e83a9d0108ac56b9538b45ead57efc8b97c5ff - Patch
References () https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-jrgj-35jx-2qq7 - () https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-jrgj-35jx-2qq7 - Exploit, Vendor Advisory
First Time Tandoor recipes
Tandoor
CPE cpe:2.3:a:tandoor:recipes:*:*:*:*:*:*:*:*

28 Jan 2025, 17:15

Type Values Removed Values Added
References () https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-jrgj-35jx-2qq7 - () https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-jrgj-35jx-2qq7 -

28 Jan 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-28 16:15

Updated : 2025-05-08 18:45


NVD link : CVE-2025-23212

Mitre link : CVE-2025-23212

CVE.ORG link : CVE-2025-23212


JSON object : View

Products Affected

tandoor

  • recipes
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

NVD-CWE-noinfo