CVE-2025-2322 is a critical vulnerability affecting the springboot-openai-chatgpt e84f6f5 application, specifically due to hard-coded credentials within the OpenController.java file. This flaw allows for remote exploitation, enabling an attacker to gain full control over the system, leading to high impacts on confidentiality, integrity, and availability. The vulnerability has a CVSS score of 9.8, indicating its severe nature, and public exploit details are available, though it is not currently listed in CISA's KEV catalog. Despite public disclosure, there is minimal community discussion or media coverage surrounding this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2024-12-29CPE matchmatch criteria | cpe:2.3:a:274056675:springboot-openai-chatgpt:2024-12-29:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.