CVE-2025-54305

An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. One of the middlewares included in this application, LocalhostAuthMiddleware, authenticates users as ionadmin if the REMOTE_ADDR property in request.META is set to 127.0.0.1, to 127.0.1.1, or to ::1. Any user with local access to the server may bypass authentication.
Configurations

Configuration 1 (hide)

cpe:2.3:a:thermofisher:torrent_suite_software:5.18.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-04 15:15

Updated : 2025-12-16 18:50


NVD link : CVE-2025-54305

Mitre link : CVE-2025-54305

CVE.ORG link : CVE-2025-54305


JSON object : View

Products Affected

thermofisher

  • torrent_suite_software
CWE
CWE-290

Authentication Bypass by Spoofing