affected: - package: ecosystem: PyPI name: freetakserver purl: pkg:pypi/freetakserver ranges: - events: - introduced: '0' type: ECOSYSTEM versions: - 0.0.1.5 - 0.1.0 - 0.1.1 - 0.1.1.0.1 - 0.1.1.0.2 - 0.1.1.0.3 - 0.1.2 - 0.1.3 - 0.1.3.9.4 - 0.1.4 - 0.1.5 - 0.1.5.1 - 0.1.5.2 - 0.1.5.3 - 0.1.5.4 - 0.1.5.5 - 0.1.5.5.1 - 0.1.5.5.2 - 0.1.5.6 - 0.1.5.7 - 0.1.5.8 - 0.1.6 - 0.1.7.3 - 0.1.8 - 0.1.8.1 - 0.1.9 - 0.1.9.1 - 0.1.9.1.5 - 0.1.9.2 - 0.1.9.2.5 - 0.1.9.5.6 - 0.1.9.8.5 - 0.1.9.9.1 - 0.1.9.9.5.5 - '0.111' - '0.112' - 0.2.0.11a0 - 0.2.0.13 - 0.2.0.17b0 - 0.2.1.0 - 0.2.1.1 - 0.2.1.2 - 0.8.13 - 0.8.19 - 0.8.19.6 - 0.8.19.6.1 - 0.8.19.6.2 - 0.8.19.6.3 - 0.8.20 - 0.8.20.1 - 0.8.21 - 0.8.22 - 0.8.23 - 0.8.50 - 0.8.50.1 - 0.8.75 - 0.8.75.1 - 0.8.76 - 0.9.9 - 0.9.9.1 - 0.9.9.2 - 1.0.3 - '1.1' - 1.1.1 - 1.1.2 - '1.2' - 1.2.0.1 - 1.2.0.2 - 1.2.5 - '1.3' - 1.3.0.5 - 1.3.0.6 - 1.5.10 - 1.5.10.1 - 1.5.10.2 - 1.5.12 - 1.7.1 - 1.7.5 - '1.8' - 1.8.1 - '1.9' - 1.9.1 - 1.9.1.5 - 1.9.5 - 1.9.5.1 - 1.9.6 - 1.9.6.1 - 1.9.7 - 1.9.8 - 1.9.8.5 - 1.9.8.6 - 1.9.8.7 - 1.9.8.8 - 1.9.9 - 1.9.9.1 - 1.9.9.1.0.1 - 1.9.9.2 - 1.9.9.3 - 1.9.9.4 - 1.9.9.5 - 1.9.9.6 - 2.0.21 - 2.0.66 - 2.0.69 - 0.2.1a1 - 0.2a1 - '2.1' - 2.1.1 - 2.1.2 - 2.1.3 - 2.1.4.5 - '2.2' - 2.2.0.1 - 2.2.1 aliases: - CVE-2022-25508 - GHSA-hggv-mcp4-vxc5 details: An access control issue in the component /ManageRoute/postRoute of FreeTAKServer v1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. id: PYSEC-2022-43054 modified: '2026-06-10T16:51:23.618348Z' published: '2022-03-11T00:15:00Z' references: - type: EVIDENCE url: https://github.com/FreeTAKTeam/FreeTakServer/issues/291 - type: REPORT url: https://github.com/FreeTAKTeam/FreeTakServer/issues/291 - type: ADVISORY url: https://github.com/advisories/GHSA-hggv-mcp4-vxc5 severity: - score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H type: CVSS_V3