Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The external storage feature allows any user to enumerate the name and content of files on the server. This vulnerability is fixed in 1.5.28.
References
Link | Resource |
---|---|
https://github.com/TandoorRecipes/recipes/commit/36e83a9d0108ac56b9538b45ead57efc8b97c5ff | Patch |
https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-jrgj-35jx-2qq7 | Exploit Vendor Advisory |
https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-jrgj-35jx-2qq7 | Exploit Vendor Advisory |
Configurations
History
08 May 2025, 18:45
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CWE | NVD-CWE-noinfo | |
References | () https://github.com/TandoorRecipes/recipes/commit/36e83a9d0108ac56b9538b45ead57efc8b97c5ff - Patch | |
References | () https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-jrgj-35jx-2qq7 - Exploit, Vendor Advisory | |
First Time |
Tandoor recipes
Tandoor |
|
CPE | cpe:2.3:a:tandoor:recipes:*:*:*:*:*:*:*:* |
28 Jan 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-jrgj-35jx-2qq7 - |
28 Jan 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-28 16:15
Updated : 2025-05-08 18:45
NVD link : CVE-2025-23212
Mitre link : CVE-2025-23212
CVE.ORG link : CVE-2025-23212
JSON object : View
Products Affected
tandoor
- recipes
CWE