CVE-2025-54955

OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition (EE) before 6.10.3 have a critical FireEdge race condition that can lead to full account takeover. By exploiting this, an unauthenticated attacker can obtain a valid JSON Web Token (JWT) belonging to a legitimate user without knowledge of their credentials.
Configurations

No configuration.

History

04 Aug 2025, 16:15

Type Values Removed Values Added
References () https://github.com/Stolichnayer/OpenNebula-Account-Takeover - () https://github.com/Stolichnayer/OpenNebula-Account-Takeover -

04 Aug 2025, 15:06

Type Values Removed Values Added
Summary
  • (es) OpenNebula Community Edition (CE) anterior a la versión 7.0.0 y Enterprise Edition (EE) anterior a la versión 6.10.3 presentan una condición crítica de ejecución de FireEdge que puede provocar la apropiación total de la cuenta. Al explotar esto, un atacante no autenticado puede obtener un JSON Web Token (JWT) válido perteneciente a un usuario legítimo sin conocer sus credenciales.

03 Aug 2025, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-03 00:15

Updated : 2025-08-04 16:15


NVD link : CVE-2025-54955

Mitre link : CVE-2025-54955

CVE.ORG link : CVE-2025-54955


JSON object : View

Products Affected

No product.

CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')