FreeTAKTeam/FreeTakServer

FreeTAKTeam/FreeTakServer

Situational Awareness Server compatible with TAK clients

CVE History

CVEPublishedCVSS v2CVSS v3
CVE-2022-255087.5 HIGH5 MEDIUM
An access control issue in the component /ManageRoute/postRoute of FreeTAKServer v1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users.
CVE-2022-255108.8 HIGH6.5 MEDIUM
FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges.