Impact
This affects Anubis in its default configuration. This enables attackers that know about this vulnerability to bypass Anubis at will.
Patches
Administrators should upgrade to version v1.15.1 as soon as possible.
Workarounds
Administrators cannot work around this issue.
Additional processes around handling regression tests are being added to the Anubis project.
Timeline
- March 31, 2025 @ 19:23 UTC: PR #180 is filed. It is instantly recognized as a recurrence of CVE-2025-24369. Coordination is made downstream distributors.
- March 31, 2024 @ 21:45 UTC: Version v1.15.1 is staged for release.
- March 31, 2024 @ 22:30 UTC: Version v1.15.1 is released, fixing the issue. Downstream distributors are advised to patch. This advisory is released.
Impact
This affects Anubis in its default configuration. This enables attackers that know about this vulnerability to bypass Anubis at will.
Patches
Administrators should upgrade to version v1.15.1 as soon as possible.
Workarounds
Administrators cannot work around this issue.
Additional processes around handling regression tests are being added to the Anubis project.
Timeline