CVE-2025-56449 (CNNVD-202509-4398)
中文标题:
Obsidian Scheduler 安全漏洞
英文标题:
A security vulnerability was identified in Obsidian Scheduler's REST API 5.0.0 thru 6.3.0. If an acc...
漏洞描述
中文描述:
Obsidian Scheduler是美国Obsidian公司的一个企业级任务调度器。 Obsidian Scheduler 5.0.0版本至6.3.0版本存在安全漏洞,该漏洞源于账户锁定后仍允许通过Basic Authentication进行身份验证,可能导致绕过MFA保护并创建特权用户。
英文描述:
A security vulnerability was identified in Obsidian Scheduler's REST API 5.0.0 thru 6.3.0. If an account is locked out due to not enrolling in MFA (e.g. after the 7-day enforcement window), the REST API still allows the use of Basic Authentication to authenticate and perform administrative actions. In particular, the default admin account was found to be locked out via the web interface but still usable through the REST API. This allowed creation of a new privileged user, bypassing MFA protections. This undermines the intended security posture of MFA enforcement.
CWE类型:
标签:
受影响产品
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
3.1 (adp)
HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-56449 |
2025-11-11 15:23:29 | 2025-11-11 07:40:44 |
| NVD | nvd_CVE-2025-56449 |
2025-11-11 15:01:04 | 2025-11-11 07:48:31 |
| CNNVD | cnnvd_CNNVD-202509-4398 |
2025-11-11 15:12:59 | 2025-11-11 08:00:14 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-202509-4398
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- data_sources: ['cve'] -> ['cve', 'nvd']