{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-17T09:06:18.330","vulnerabilities":[{"cve":{"id":"CVE-2025-54955","sourceIdentifier":"cve@mitre.org","published":"2025-08-03T00:15:25.633","lastModified":"2026-04-15T00:35:42.020","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition (EE) before 6.10.3 have a critical FireEdge race condition that can lead to full account takeover. By exploiting this, an unauthenticated attacker can obtain a valid JSON Web Token (JWT) belonging to a legitimate user without knowledge of their credentials."},{"lang":"es","value":"OpenNebula Community Edition (CE) anterior a la versión 7.0.0 y Enterprise Edition (EE) anterior a la versión 6.10.3 presentan una condición crítica de ejecución de FireEdge que puede provocar la apropiación total de la cuenta. Al explotar esto, un atacante no autenticado puede obtener un JSON Web Token (JWT) válido perteneciente a un usuario legítimo sin conocer sus credenciales."}],"metrics":{"cvssMetricV31":[{"source":"cve@mitre.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}]},"weaknesses":[{"source":"cve@mitre.org","type":"Secondary","description":[{"lang":"en","value":"CWE-362"}]}],"references":[{"url":"https://docs.opennebula.io/6.10/intro_release_notes/release_notes_enterprise/resolved_issues_6103.html","source":"cve@mitre.org"},{"url":"https://github.com/OpenNebula/one","source":"cve@mitre.org"},{"url":"https://github.com/OpenNebula/one/commit/81058d9705e7ac619d294423de28b76d88f613b6","source":"cve@mitre.org"},{"url":"https://github.com/OpenNebula/one/releases/tag/release-7.0.0","source":"cve@mitre.org"},{"url":"https://github.com/Stolichnayer/OpenNebula-Account-Takeover","source":"cve@mitre.org"},{"url":"https://github.com/Stolichnayer/OpenNebula-Account-Takeover","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}}]}