Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 02 Jan 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Turms-im
Turms-im turms |
|
| CPEs | cpe:2.3:a:turms-im:turms:0.10.0-snapshot:*:*:*:*:*:*:* | |
| Vendors & Products |
Turms-im
Turms-im turms |
Sun, 21 Dec 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Turms
Turms turms Server |
|
| Vendors & Products |
Turms
Turms turms Server |
Fri, 19 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-256 CWE-532 |
|
| Metrics |
cvssV3_1
|
Fri, 19 Dec 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Turms Server v0.10.0-SNAPSHOT and earlier contains a plaintext password storage vulnerability in the administrator authentication system. The BaseAdminService class caches administrator passwords in plaintext within AdminInfo objects to optimize authentication performance. Upon successful login, raw passwords are stored unencrypted in memory in the rawPassword field. Attackers with local system access can extract these passwords through memory dumps, heap analysis, or debugger attachment, bypassing bcrypt protection. | |
| References |
|
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-19T15:57:25.539Z
Reserved: 2025-12-08T00:00:00.000Z
Link: CVE-2025-66910
Updated: 2025-12-19T15:56:47.831Z
Status : Analyzed
Published: 2025-12-19T15:15:56.790
Modified: 2026-01-02T19:50:30.200
Link: CVE-2025-66910
No data.
OpenCVE Enrichment
Updated: 2025-12-21T21:14:48Z