CVE Vulnerabilities

CVE-2025-58060

Improper Authentication

Published: Sep 11, 2025 | Modified: Nov 04, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
8 IMPORTANT
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, when the AuthType is set to anything but Basic, if the request contains an Authorization: Basic ... header, the password is not checked. This results in authentication bypass. Any configuration that allows an AuthType that is not Basic is affected. Version 2.4.13 fixes the issue.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
CupsOpenprinting*2.4.13 (excluding)
Red Hat Enterprise Linux 10RedHatcups-1:2.4.10-11.el10_0.1*
Red Hat Enterprise Linux 7 Extended Lifecycle SupportRedHatcups-1:1.6.3-52.el7_9.1*
Red Hat Enterprise Linux 8RedHatcups-1:2.2.6-63.el8_10*
Red Hat Enterprise Linux 8RedHatcups-1:2.2.6-63.el8_10*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatcups-1:2.2.6-33.el8_2.3*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatcups-1:2.2.6-38.el8_4.3*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatcups-1:2.2.6-38.el8_4.3*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatcups-1:2.2.6-45.el8_6.6*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatcups-1:2.2.6-45.el8_6.6*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatcups-1:2.2.6-45.el8_6.6*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatcups-1:2.2.6-51.el8_8.5*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatcups-1:2.2.6-51.el8_8.5*
Red Hat Enterprise Linux 9RedHatcups-1:2.3.3op2-33.el9_6.1*
Red Hat Enterprise Linux 9RedHatcups-1:2.3.3op2-33.el9_6.1*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatcups-1:2.3.3op2-13.el9_0.4*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatcups-1:2.3.3op2-16.el9_2.4*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatcups-1:2.3.3op2-27.el9_4.1*
Red Hat OpenShift Container Platform 4.12RedHatrhcos-412.86.202510291903-0*
RHOSS-1.36-RHEL-8RedHatopenshift-serverless-1/logic-data-index-ephemeral-rhel8:1.36.0-11*
RHOSS-1.36-RHEL-8RedHatopenshift-serverless-1/logic-data-index-postgresql-rhel8:1.36.0-11*
RHOSS-1.36-RHEL-8RedHatopenshift-serverless-1/logic-db-migrator-tool-rhel8:1.36.0-11*
RHOSS-1.36-RHEL-8RedHatopenshift-serverless-1/logic-jobs-service-ephemeral-rhel8:1.36.0-10*
RHOSS-1.36-RHEL-8RedHatopenshift-serverless-1/logic-jobs-service-postgresql-rhel8:1.36.0-10*
RHOSS-1.36-RHEL-8RedHatopenshift-serverless-1/logic-kn-workflow-cli-artifacts-rhel8:1.36.0-4*
RHOSS-1.36-RHEL-8RedHatopenshift-serverless-1/logic-management-console-rhel8:1.36.0-9*
RHOSS-1.36-RHEL-8RedHatopenshift-serverless-1/logic-operator-bundle:1.36.0-12*
RHOSS-1.36-RHEL-8RedHatopenshift-serverless-1/logic-rhel8-operator:1.36.0-18*
RHOSS-1.36-RHEL-8RedHatopenshift-serverless-1/logic-swf-builder-rhel8:1.36.0-11*
RHOSS-1.36-RHEL-8RedHatopenshift-serverless-1/logic-swf-devmode-rhel8:1.36.0-7*
CupsUbuntudevel*
CupsUbuntuesm-infra/bionic*
CupsUbuntuesm-infra/focal*
CupsUbuntuesm-infra/xenial*
CupsUbuntujammy*
CupsUbuntunoble*
CupsUbuntuplucky*
CupsUbuntuupstream*

Potential Mitigations

References