216.73.216.233

CVE-2025-11240

· Published 02/10/2025 13:15 · Modified 02/10/2025 19:11

Labels: CVE-2025-11240 2025-10-02CVE-2025-11240CWE-601[email protected]

Essential information

Published
02/10/2025 13:15
Modified
02/10/2025 19:11
Author
Creator
CVSS
5.3 MEDIUM (v3) 5.3 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An open redirect vulnerability existed in KNIME Business Hub prior to version 1.16.0. An unauthenticated remote attacker could craft a link to a legitimate KNIME Business Hub installation which, when opened by the user, redirects the user to a page of the attackers choice. This might open the possibility for fishing or other similar attacks. The problem has been fixed in KNIME Business Hub 1.16.0.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
knime / business hub cpe:2.3:a:knime:business_hub:<1.16.0:*:*:*:*:*:*:*

References