CVE ID | CVE-2025-1774 |
Publication date | 17 March 2025 |
Vendor | NASK - PIB |
Product | BotSense |
Vulnerable versions | All before 2.8.0 |
Vulnerability type (CWE) | Improper Neutralization of Value Delimiters (CWE-142) |
Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in NASK BotSense software and participated in coordination of its disclosure.
Incorrect string encoding vulnerability CVE-2025-1774 allows injection of an additional field separator character or value in the content of some fields of the generated event. A field with additional field separator characters or values can be included in the extraData
field.
This issue affects BotSense in versions before 2.8.0.
Credits
We thank Piotr Koper for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.