CVE-2025-0509
EUVD-2025-023204.02.2025, 20:15
A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| sparkle-project | sparkle | 𝑥 < 2.6.4 |
| netapp | hci_compute_node | - |
| netapp | oncommand_workflow_automation | - |
| netapp | hci_compute_node | - |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| openjdk-13 |
| ||||||||||||
| openjdk-16 |
| ||||||||||||
| openjdk-17 |
| ||||||||||||
| openjdk-18 |
| ||||||||||||
| openjdk-19 |
| ||||||||||||
| openjdk-21 |
| ||||||||||||
| openjdk-22 |
| ||||||||||||
| openjdk-23 |
| ||||||||||||
| openjdk-8 |
| ||||||||||||
| openjdk-9 |
| ||||||||||||
| openjdk-lts |
|
Common Weakness Enumeration