MEDIUM🇵🇱 Wersja polska

CVE-2025-1300

CVSS 6.1v3.1pub. 2025-02-28upd. 2025-11-14

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. The CodeChecker web server contains an open redirect vulnerability due to missing protections against multiple slashes after the product name in the URL. This results in bypassing the protections against CVE-2021-28861, leading to the same open redirect pathway. This issue affects CodeChecker: through 6.24.5.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  • Ericsson Codechecker

    APP
    Ericsson
    < 6.24.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-25660CRITICAL9.3PL ✓same product

Ericsson CodeChecker — Authentication Bypass umożliwiający eskalację uprawnień

CVE-2024-10081CRITICAL10.0PL ✓same product

Authentication bypass w Ericsson CodeChecker — pełny dostęp do API

CVE-2024-53829HIGH8.2same product

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Cla...

CVE-2024-10082HIGH8.7same product

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Cla...

CVE-2025-40843MEDIUM5.9same product

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Cla...