216.73.217.22

CVE-2025-1293

· Published 20/02/2025 01:15 · Modified 20/02/2025 01:15

Labels: CVE-2025-1293 2025-02-20CVE-2025-1293CWE-1390[email protected]

Essential information

Published
20/02/2025 01:15
Modified
20/02/2025 01:15
Author
Creator
CVSS
8.2 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N

CVSS metrics

Description

Hermes versions up to 0.4.0 improperly validated the JWT provided when using the AWS ALB authentication mode, potentially allowing for authentication bypass. This vulnerability, CVE-2025-1293, was fixed in Hermes 0.5.0.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References