Logic Flaw in MeterSphere Continuous Testing Platform by MeterSphere
CVE-2025-62604
What is CVE-2025-62604?
MeterSphere, an open-source continuous testing platform, is affected by a significant logic flaw that allows an unauthenticated attacker to gain unauthorized access to arbitrary user information. This vulnerability can enable attackers to log in to the system, impersonating any user without proper authentication. The issue has been addressed in the release of version 2.10.25-lts, which includes necessary patches to mitigate the risk posed by this flaw. It is crucial for users to update to this version to ensure their systems remain secure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
metersphere < 2.10.25-lts
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
