OPSI before 4.3 allows any client to retrieve any...
Critical severity
Unreviewed
Published
Sep 8, 2025
to the GitHub Advisory Database
•
Updated Sep 9, 2025
Description
Published by the National Vulnerability Database
Sep 8, 2025
Published to the GitHub Advisory Database
Sep 8, 2025
Last updated
Sep 9, 2025
OPSI before 4.3 allows any client to retrieve any ProductPropertyState, including those of other clients. This can lead to privilege escalation if any ProductPropertyState contains a secret only intended to be accessible by a subset of clients. One example of this is a domain join account password for the windomain package.
References