Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The external storage feature allows any user to enumerate the name and content of files on the server. This vulnerability is fixed in 1.5.28.
Metrics
Affected Vendors & Products
References
History
Thu, 08 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tandoor
Tandoor recipes |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:tandoor:recipes:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tandoor
Tandoor recipes |
Tue, 28 Jan 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Jan 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The external storage feature allows any user to enumerate the name and content of files on the server. This vulnerability is fixed in 1.5.28. | |
| Title | Tandoor Recipes - Local file disclosure - Users can read the content of any file on the server | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-01-28T15:29:07.948Z
Updated: 2025-01-28T16:10:06.786Z
Reserved: 2025-01-13T17:15:41.051Z
Link: CVE-2025-23212
Updated: 2025-01-28T16:09:44.630Z
Status : Analyzed
Published: 2025-01-28T16:15:41.080
Modified: 2025-05-08T18:45:54.433
Link: CVE-2025-23212
No data.