Home

Description

User with CREATE and no UPDATE privilege for Pools, Connections, Variables could update existing records via bulk create API with overwrite action.

PUBLISHED Reserved 2025-10-15 | Published 2025-10-30 | Updated 2025-10-30 | Assigner apache

Problem types

CWE-250: Execution with Unnecessary Privileges

Product status

Default status
unaffected

3.0.0 (semver) before 3.1.1
affected

Credits

Maciej Kawka finder

References

lists.apache.org/thread/3v58249qscyn1hg240gh8hqg9pb4okcr vendor-advisory

cve.org (CVE-2025-62503)

nvd.nist.gov (CVE-2025-62503)

Download JSON