FreshRSS: Unauthenticated users can view default user's information
Published Sep 29, 2025
7.5
HIGHCVSS 3.1
EPSS 0.43%
Description
FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below expose information about feeds and tags of default admin users, due to lack of access checking in the FreshRSS_Auth::hasAccess() function used by some of the tag/feed related endpoints. FreshRSS controllers usually have a defined firstAction() method with an override to make sure that every action requires access. If one doesn't, then every action has to check for access manually, and certain endpoints use neither the firstAction() method, or do they perform a manual access check. This issue is fixed in version 1.27.0.
Affected products
-
- Version < 1.27.0StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://github.com/FreshRSS/FreshRSS/pull/7768 x_refsource_MISCPatch
- https://github.com/FreshRSS/FreshRSS/releases/tag/1.27.0 x_refsource_MISCRelease Notes
- https://github.com/FreshRSS/FreshRSS/security/advisories/GHSA-jf4v-f8p2-8xvq exploitx_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/FreshRSS/FreshRSS/pull/7768 | x_refsource_MISCPatch | |
| https://github.com/FreshRSS/FreshRSS/releases/tag/1.27.0 | x_refsource_MISCRelease Notes | |
| https://github.com/FreshRSS/FreshRSS/security/advisories/GHSA-jf4v-f8p2-8xvq | exploitx_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.