CVE-2025-3324

Source
https://cve.org/CVERecord?id=CVE-2025-3324
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-3324.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-3324
Published
2025-04-06T22:31:04Z
Modified
2026-08-28T11:46:47Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
godcheese/code-projects Nimrod FileRestController.java unrestricted upload
Details

A vulnerability, which was classified as critical, has been found in godcheese/code-projects Nimrod 0.8. Affected by this issue is some unknown functionality of the file FileRestController.java. The manipulation of the argument File leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

Database specific
{
    "cna_assigner":  "VulDB",
    "cwe_ids":  [
        "CWE-284",
        "CWE-434"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/3xxx/CVE-2025-3324.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "introduced":  "0.8"
                },
                {
                    "last_affected":  "0.8"
                },
                {
                    "introduced":  "0.8"
                },
                {
                    "last_affected":  "0.8"
                }
            ],
            "source":  "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/godcheese/nimrod

Affected ranges

Type
GIT
Repo
https://github.com/godcheese/nimrod
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:godcheese:nimrod:0.8:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "0.8"
        },
        {
            "last_affected":  "0.8"
        }
    ],
    "source":  "CPE_STRING"
}

Affected versions

0.*
0.8
v0.*
v0.8.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-3324.json"