CVE-2025-7552 Details
Description
A vulnerability was found in Dromara Northstar up to 7.3.5. It has been rated as critical. Affected by this issue is the function preHandle of the file northstar-main/src/main/java/org/dromara/northstar/web/interceptor/AuthorizationInterceptor.java of the component Path Handler. The manipulation of the argument Request leads to improper access controls. The attack may be launched remotely. Upgrading to version 7.3.6 is able to address this issue. The patch is identified as 8d521bbf531de59b09b8629a9cbf667870ad2541. It is recommended to upgrade the affected component.
A critical authentication bypass vulnerability has been identified in Dromara Northstar versions through 7.3.5. The issue resides in the AuthorizationInterceptor class, specifically within the preHandle method. This vulnerability allows unauthorized access to the '/northstar/*' API endpoints by manipulating the request URI to bypass access controls. The flaw can be exploited remotely, leading to unauthorized access and potential information leakage, such as log data, from the application.
Users are advised to upgrade to Dromara Northstar version 7.3.6, which addresses this vulnerability by correcting the authorization path handling. The updated version is available for download on the project's Gitee release page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 14, 2025CISA-ADP
Assessed Jul 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gitee.com/dromara/northstar/issues/ICCQ4E | CISA-ADP | ExploitIssue TrackingTechnical DescriptionVendor |
| https://gitee.com/dromara/northstar/issues/ICCQ4E#note_42855013_link | CISA-ADP | ExploitIssue TrackingTechnical DescriptionVendor |
| https://gitee.com/dromara/northstar/commit/8d521bbf531de59b09b8629a9cbf667870ad2541 | [email protected] | Source CodeVendor |
| https://gitee.com/dromara/northstar/issues/ICCQ4E | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://gitee.com/dromara/northstar/issues/ICCQ4E#note_42855013_link | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://gitee.com/dromara/northstar/releases/tag/v7.3.6 | [email protected] | Release NotesVendor |
| https://vuldb.com/?ctiid.316250 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/?id.316250 | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Dromara Northstar | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2025 | CVE Modified | CISA-ADP |
| Jul 14, 2025 | New CVE Received | [email protected] |
Volerion