Exposure of Sensitive Information to an Unauthorized Actor
CVE-2025-10952
Summary
A security flaw has been discovered in geyang ml-logger version 0.7.0rc1 and after. Affected by this issue is the function "stream_handler()" of the file "ml_logger/server.py" of the component File Handler. Performing manipulation of the argument key results in information disclosure. The attack can be initiated remotely. The exploit has been released to the public and may be exploited. Continuous delivery with rolling releases is used by this product.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- NONE
- LOW
- NONE
CWE-200 - Information Exposure
An information exposure vulnerability is categorized as an information flow (IF) weakness, which can potentially allow unauthorized access to otherwise classified information in the application, such as confidential personal information (demographics, financials, health records, etc.), business secrets, and the application's internal environment.
Advisory Timeline
- Published