← العودة للجدول
CVE-2025-24977
CVE-2025-24977 — OpenCTI is an open cyber threat intelligence (CTI) platform. Prior to version 6.
📅 2025-05-05
🔴 Critical 🔥 No NVD Exploit Containers CVSS 9.1 🎯 EPSS 0.53%

📋 الوصف الكامل

OpenCTI is an open cyber threat intelligence (CTI) platform. Prior to version 6.4.11 any user with the capability `manage customizations` can execute commands on the underlying infrastructure where OpenCTI is hosted and can access internal server side secrets by misusing the web-hooks. Since the malicious user gets a root shell inside a container this opens up the the infrastructure environment fo

💻 الأنظمة المتأثرة

Intel

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2025-24977

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v6.4.11

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←