blob: 013b6bb85aae366973efa0633b6602a4809a65dd [file]
id: GO-2025-3945
modules:
- module: github.com/SpectoLabs/hoverfly
versions:
- fixed: 1.12.0
vulnerable_at: 1.11.3
summary: |-
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when
--auth is enabled in github.com/SpectoLabs/hoverfly
cves:
- CVE-2025-54376
ghsas:
- GHSA-jxmr-2h4q-rhxp
references:
- advisory: https://github.com/SpectoLabs/hoverfly/security/advisories/GHSA-jxmr-2h4q-rhxp
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-54376
- fix: https://github.com/SpectoLabs/hoverfly/commit/ffc2cc34563de67fe1a04f7ba5d78fa2d4564424
source:
id: GHSA-jxmr-2h4q-rhxp
created: 2025-09-17T12:15:42.25386-04:00
review_status: UNREVIEWED