Metrics
Affected Vendors & Products
Fri, 03 Apr 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:rocketsoftware:trufusion_enterprise:*:*:*:*:*:*:*:* |
Wed, 11 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-918 | |
| Metrics |
cvssV3_1
|
Wed, 18 Feb 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rocketsoftware
Rocketsoftware trufusion Enterprise |
|
| Vendors & Products |
Rocketsoftware
Rocketsoftware trufusion Enterprise |
Tue, 17 Feb 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections. However, the proxy is misconfigured in a way that allows specifying absolute URLs in the HTTP request line, causing the proxy to load the given resource. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-03-11T15:19:31.478Z
Reserved: 2025-04-05T00:00:00.000Z
Link: CVE-2025-32355
Updated: 2026-03-06T17:53:34.509Z
Status : Analyzed
Published: 2026-02-17T20:22:03.047
Modified: 2026-04-03T11:34:34.503
Link: CVE-2025-32355
No data.
OpenCVE Enrichment
Updated: 2026-02-18T10:44:16Z