Description
The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially aiding reconnaissance.
Problem types
Generation of Error Message Containing Sensitive Information
Product status
5.0.0 (semver) before 5.0.3
Timeline
| 2025-10-16: | Reported to Red Hat. |
| 2025-10-14: | Made public. |
Credits
Red Hat would like to thank Adam Jenkins for reporting this issue.
References
access.redhat.com/security/cve/CVE-2025-62397
bugzilla.redhat.com/show_bug.cgi?id=2404430 (RHBZ#2404430)