Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 01 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Dec 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openobserve
Openobserve openobserve |
|
| Vendors & Products |
Openobserve
Openobserve openobserve |
Sat, 29 Nov 2025 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenObserve is a cloud-native observability platform. Prior to version 0.16.0, organization invitation tokens do not expire once issued, remain valid even after the invited user is removed from the organization, and allow multiple invitations to the same email with different roles where all issued links remain valid simultaneously. This results in broken access control where a removed or demoted user can regain access or escalate privileges. This issue has been patched in version 0.16.0. | |
| Title | OpenObserve's Invite Token Lifecycle Misconfiguration | |
| Weaknesses | CWE-284 CWE-613 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-01T15:33:42.150Z
Reserved: 2025-11-24T23:01:29.679Z
Link: CVE-2025-66223
Updated: 2025-12-01T15:33:34.636Z
Status : Awaiting Analysis
Published: 2025-11-29T03:16:00.227
Modified: 2025-12-01T15:39:33.110
Link: CVE-2025-66223
No data.
OpenCVE Enrichment
Updated: 2025-12-01T15:18:20Z