CVE Vulnerabilities

CVE-2025-27581

Direct Request ('Forced Browsing')

Published: Apr 24, 2025 | Modified: Apr 24, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 allows users who lack the InET role to access the InET module via direct requests to known endpoints.

Weakness

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Potential Mitigations

References