CVE-2025-23012: Fedora Repository fedoraIntCallUser default credentials
Fedora Repository 3.8.x includes a service account (fedoraIntCallUser) with default credentials and privileges to read read local files by manipulating datastreams. Fedora Repository 3.8.1 was released on 2015-06-11 and is no longer maintained. Migrate to a currently supported version (6.5.1 as of 2025-01-23).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23012?
CVE-2025-23012 has been classified as a high severity vulnerability due to its exploitation potential through default credentials.
How do I fix CVE-2025-23012?
To fix CVE-2025-23012, you should migrate to a currently supported version of Fedora Repository, as version 3.8.1 is no longer maintained.
What are the risks associated with CVE-2025-23012?
The risks associated with CVE-2025-23012 include unauthorized access to local files through manipulation of datastreams.
What versions are affected by CVE-2025-23012?
CVE-2025-23012 affects Fedora Repository version 3.8.x up to and including 3.8.1.
Is there a patch available for CVE-2025-23012?
No, there is no patch available for CVE-2025-23012 since Fedora Repository 3.8.1 is no longer maintained.