CVE-2025-54305

A

n issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. One of the middlewares included in this application, LocalhostAuthMiddleware, authenticates users as ionadmin if the REMOTE_ADDR property in request.META is set to 127.0.0.1, to 127.0.1.1, or to ::1. Any user with local access to the server may bypass authentication.

Configurations

Configuration 1 (hide)

cpe:2.3:a:thermofisher:torrent_suite_software:5.18.1:*:*:*:*:*:*:*

History

16 Dec 2025, 18:50

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-04 15:15

Updated : 2025-12-16 18:50


NVD link : CVE-2025-54305

Mitre link : CVE-2025-54305

CVE.ORG link : CVE-2025-54305


JSON object : View

CWE
CWE-290

Authentication Bypass by Spoofing