CVE-2025-1300 – CodeChecker Open Redirect Vulnerability

The following table lists the changes that have been made to the
CVE-2025-1300 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by 85b1779b-6ecd-4f52-bcc5-73eac4659dcf

    Feb. 28, 2025

    Action Type Old Value New Value
    Added Description CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.

    The CodeChecker web server contains an open redirect vulnerability due to missing protections against multiple slashes after the product name in the URL. This results in bypassing the protections against CVE-2021-28861, leading to the same open redirect pathway.

    This issue affects CodeChecker: through 6.24.5.

    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
    Added CWE CWE-601
    Added Reference https://github.com/Ericsson/codechecker/security/advisories/GHSA-g839-x3p3-g5fm
Share the Post:

Related Posts