Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 16 Dec 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Thermofisher torrent Suite Software
|
|
| CPEs | cpe:2.3:a:thermofisher:torrent_suite_software:5.18.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Thermofisher torrent Suite Software
|
Fri, 05 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-290 | |
| Metrics |
cvssV3_1
|
Thu, 04 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Thermofisher
Thermofisher torrent Suite |
|
| Vendors & Products |
Thermofisher
Thermofisher torrent Suite |
Thu, 04 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. One of the middlewares included in this application, LocalhostAuthMiddleware, authenticates users as ionadmin if the REMOTE_ADDR property in request.META is set to 127.0.0.1, to 127.0.1.1, or to ::1. Any user with local access to the server may bypass authentication. | |
| References |
|
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-05T19:07:10.828Z
Reserved: 2025-07-18T00:00:00.000Z
Link: CVE-2025-54305
Updated: 2025-12-05T19:06:16.405Z
Status : Analyzed
Published: 2025-12-04T15:15:58.893
Modified: 2025-12-16T18:50:09.257
Link: CVE-2025-54305
No data.
OpenCVE Enrichment
Updated: 2025-12-04T21:37:52Z