CVE-2025-7552: Dromara Northstar Path AuthorizationInterceptor.java preHandle access control
A vulnerability was found in Dromara Northstar up to 7.3.5. It has been rated as critical. Affected by this issue is the function preHandle of the file northstar-main/src/main/java/org/dromara/northstar/web/interceptor/AuthorizationInterceptor.java of the component Path Handler. The manipulation of the argument Request leads to improper access controls. The attack may be launched remotely. Upgrading to version 7.3.6 is able to address this issue. The patch is identified as 8d521bbf531de59b09b8629a9cbf667870ad2541. It is recommended to upgrade the affected component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7552?
CVE-2025-7552 has been rated as critical.
Which versions of Dromara Northstar are affected by CVE-2025-7552?
CVE-2025-7552 affects Dromara Northstar up to version 7.3.5.
How do I fix CVE-2025-7552?
To fix CVE-2025-7552, upgrade to the latest version of Dromara Northstar beyond 7.3.5.
What component is impacted by CVE-2025-7552?
CVE-2025-7552 impacts the function preHandle in the AuthorizationInterceptor class of Dromara Northstar.
What type of vulnerability is CVE-2025-7552?
CVE-2025-7552 is a critical vulnerability in the Path Handler component of Dromara Northstar.