Database/Control plane, storage & DevOps
Dell CloudLink (restricted shell breakout): A privileged user breaks out of the restricted shell into a full command
CVSS 9.1CVE-2025-45378Control plane, storage & DevOpscurated
Impact
A privileged user breaks out of the restricted shell into a full command shell on the CloudLink server and escalates. Reachable over the network when SSH is enabled with web credentials.
Who can reach it
SSH to the CloudLink appliance with a known privileged password.
What to do
Upgrade CloudLink past 8.1.2 (fixed in 8.2). Disable SSH on the appliance if you do not operationally need it - that removes the network path entirely.
References
Related entries
- Dell CloudLink (CLI escape): A privileged user with a known password escapes the CLI and takes control of the CloudLinkCVE-2025-46364 · Dell CloudLink (CLI escape)Critical
- OAuth2-Proxy: skip_auth_routes route matching flawCVE-2025-54576 · OAuth2-ProxyCritical
- Apache Airflow: logout does not invalidate the session JWT, so an intercepted token stays usableCVE-2025-57735 · Apache Airflow (API server JWT session handling on logout)Critical
- HashiCorp Vault: Root-namespace operator with write on sys/audit gains code execution on the Vault hostCVE-2025-6000 · HashiCorp VaultCritical
- Lantronix EDS3000PS serial-to-Ethernet device server: Full bypass of the management-page loginCVE-2025-67039 · Lantronix EDS3000PS serial-to-Ethernet device serverCritical
- Palo Alto PAN-OS: GlobalProtect portal/gateway auth bypassCVE-2026-0257 · Palo Alto PAN-OSCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.