CVE-2025-13809 - orionsec orion-ops SSH Connection MachineInfoController.java server-side request...

CVE-2025-13809 - orionsec orion-ops SSH Connection MachineInfoController.java server-side request...

CVE ID : CVE-2025-13809 Published : Dec. 1, 2025, 6:15 a.m. | 1 hour, 26 minutes ago Description : A vulnerability has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected by this issue is some unknown functionality of the file orion-ops-api/orion-ops-web/src/main/java/cn/orionsec/ops/controller/MachineInfoController.java of the component SSH Connection Handler. Such manipulation of the argument host/sshPort/username/password/authType leads to server-side request forgery. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. A patch should be applied to remediate this issue. The vendor was contacted early about this disclosure but did not respond in any way. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
Dec. 1, 2025
Affected Product: java

Source: Telegram CVE Monitor