{
  "document": {
    "aggregate_severity": {
      "text": "High"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/almalinux9.2esu/vex/2025/cve-2025-27817-els_os-almalinux9_2esu.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-04-03T16:46:35Z",
      "generator": {
        "date": "2026-04-03T16:46:35Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2025-27817-ELS_OS-ALMALINUX9.2ESU",
      "initial_release_date": "2025-06-10T07:55:00Z",
      "revision_history": [
        {
          "date": "2025-06-10T07:55:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-04-02T08:59:51Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-04-03T16:46:35Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "Security update on CVE-2025-27817"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "AlmaLinux 9.2",
                "product": {
                  "name": "AlmaLinux 9.2",
                  "product_id": "AlmaLinux-9.2",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:almalinux:almalinux:9.2:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "AlmaLinux"
          }
        ],
        "category": "vendor",
        "name": "AlmaLinux OS Foundation"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "file-devel-0:5.39-12.1.el9_2.tuxcare.els1.x86_64",
                "product": {
                  "name": "file-devel-0:5.39-12.1.el9_2.tuxcare.els1.x86_64",
                  "product_id": "file-devel-0:5.39-12.1.el9_2.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/file-devel@5.39-12.1.el9_2.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "file-0:5.39-12.1.el9_2.tuxcare.els1.x86_64",
                "product": {
                  "name": "file-0:5.39-12.1.el9_2.tuxcare.els1.x86_64",
                  "product_id": "file-0:5.39-12.1.el9_2.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/file@5.39-12.1.el9_2.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "file-libs-0:5.39-12.1.el9_2.tuxcare.els1.x86_64",
                "product": {
                  "name": "file-libs-0:5.39-12.1.el9_2.tuxcare.els1.x86_64",
                  "product_id": "file-libs-0:5.39-12.1.el9_2.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/file-libs@5.39-12.1.el9_2.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "file-static-0:5.39-12.1.el9_2.tuxcare.els1.x86_64",
                "product": {
                  "name": "file-static-0:5.39-12.1.el9_2.tuxcare.els1.x86_64",
                  "product_id": "file-static-0:5.39-12.1.el9_2.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/file-static@5.39-12.1.el9_2.tuxcare.els1?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "file-devel-0:5.39-12.1.el9_2.tuxcare.els1.i686",
                "product": {
                  "name": "file-devel-0:5.39-12.1.el9_2.tuxcare.els1.i686",
                  "product_id": "file-devel-0:5.39-12.1.el9_2.tuxcare.els1.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/file-devel@5.39-12.1.el9_2.tuxcare.els1?arch=i686"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "file-libs-0:5.39-12.1.el9_2.tuxcare.els1.i686",
                "product": {
                  "name": "file-libs-0:5.39-12.1.el9_2.tuxcare.els1.i686",
                  "product_id": "file-libs-0:5.39-12.1.el9_2.tuxcare.els1.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/file-libs@5.39-12.1.el9_2.tuxcare.els1?arch=i686"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "i686"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "python3-file-magic-0:5.39-12.1.el9_2.tuxcare.els1.noarch",
                "product": {
                  "name": "python3-file-magic-0:5.39-12.1.el9_2.tuxcare.els1.noarch",
                  "product_id": "python3-file-magic-0:5.39-12.1.el9_2.tuxcare.els1.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/python3-file-magic@5.39-12.1.el9_2.tuxcare.els1?arch=noarch"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "noarch"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "file-devel-0:5.39-12.1.el9_2.tuxcare.els1.x86_64 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:file-devel-0:5.39-12.1.el9_2.tuxcare.els1.x86_64"
        },
        "product_reference": "file-devel-0:5.39-12.1.el9_2.tuxcare.els1.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "file-devel-0:5.39-12.1.el9_2.tuxcare.els1.i686 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:file-devel-0:5.39-12.1.el9_2.tuxcare.els1.i686"
        },
        "product_reference": "file-devel-0:5.39-12.1.el9_2.tuxcare.els1.i686",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "file-0:5.39-12.1.el9_2.tuxcare.els1.x86_64 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:file-0:5.39-12.1.el9_2.tuxcare.els1.x86_64"
        },
        "product_reference": "file-0:5.39-12.1.el9_2.tuxcare.els1.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python3-file-magic-0:5.39-12.1.el9_2.tuxcare.els1.noarch as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:python3-file-magic-0:5.39-12.1.el9_2.tuxcare.els1.noarch"
        },
        "product_reference": "python3-file-magic-0:5.39-12.1.el9_2.tuxcare.els1.noarch",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "file-libs-0:5.39-12.1.el9_2.tuxcare.els1.x86_64 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:file-libs-0:5.39-12.1.el9_2.tuxcare.els1.x86_64"
        },
        "product_reference": "file-libs-0:5.39-12.1.el9_2.tuxcare.els1.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "file-libs-0:5.39-12.1.el9_2.tuxcare.els1.i686 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:file-libs-0:5.39-12.1.el9_2.tuxcare.els1.i686"
        },
        "product_reference": "file-libs-0:5.39-12.1.el9_2.tuxcare.els1.i686",
        "relates_to_product_reference": "AlmaLinux-9.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "file-static-0:5.39-12.1.el9_2.tuxcare.els1.x86_64 as a component of AlmaLinux 9.2",
          "product_id": "AlmaLinux-9.2:file-static-0:5.39-12.1.el9_2.tuxcare.els1.x86_64"
        },
        "product_reference": "file-static-0:5.39-12.1.el9_2.tuxcare.els1.x86_64",
        "relates_to_product_reference": "AlmaLinux-9.2"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2025-27817",
      "cwe": {
        "id": "CWE-918",
        "name": "Server-Side Request Forgery (SSRF)"
      },
      "notes": [
        {
          "category": "description",
          "text": "A possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client. Apache Kafka Clients accept configuration data for setting the SASL/OAUTHBEARER connection with the brokers, including \"sasl.oauthbearer.token.endpoint.url\" and \"sasl.oauthbearer.jwks.endpoint.url\". Apache Kafka allows clients to read an arbitrary file and return the content in the error log, or sending requests to an unintended location. In applications where Apache Kafka Clients configurations can be specified by an untrusted party, attackers may use the \"sasl.oauthbearer.token.endpoint.url\" and \"sasl.oauthbearer.jwks.endpoint.url\" configuratin to read arbitrary contents of the disk and environment variables or make requests to an unintended location. In particular, this flaw may be used in Apache Kafka Connect to escalate from REST API access to filesystem/environment/URL access, which may be undesirable in certain environments, including SaaS products. \nSince Apache Kafka 3.9.1/4.0.0, we have added a system property (\"-Dorg.apache.kafka.sasl.oauthbearer.allowed.urls\") to set the allowed urls in SASL JAAS configuration. In 3.9.1, it accepts all urls by default for backward compatibility. However in 4.0.0 and newer, the default value is empty list and users have to set the allowed urls explicitly.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        },
        {
          "category": "other",
          "text": "TuxCare has assessed that this vulnerability does not impact any currently supported TuxCare products. This evaluation may change as new information becomes available. For additional details regarding this vulnerability and affected products, refer to the provided references.",
          "title": "Statement"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "AlmaLinux-9.2:file-0:5.39-12.1.el9_2.tuxcare.els1.x86_64",
          "AlmaLinux-9.2:file-devel-0:5.39-12.1.el9_2.tuxcare.els1.i686",
          "AlmaLinux-9.2:file-devel-0:5.39-12.1.el9_2.tuxcare.els1.x86_64",
          "AlmaLinux-9.2:file-libs-0:5.39-12.1.el9_2.tuxcare.els1.i686",
          "AlmaLinux-9.2:file-libs-0:5.39-12.1.el9_2.tuxcare.els1.x86_64",
          "AlmaLinux-9.2:file-static-0:5.39-12.1.el9_2.tuxcare.els1.x86_64",
          "AlmaLinux-9.2:python3-file-magic-0:5.39-12.1.el9_2.tuxcare.els1.noarch"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2025-27817"
        }
      ],
      "release_date": "2025-06-10T07:55:00Z",
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "AlmaLinux-9.2:file-0:5.39-12.1.el9_2.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:file-devel-0:5.39-12.1.el9_2.tuxcare.els1.i686",
            "AlmaLinux-9.2:file-devel-0:5.39-12.1.el9_2.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:file-libs-0:5.39-12.1.el9_2.tuxcare.els1.i686",
            "AlmaLinux-9.2:file-libs-0:5.39-12.1.el9_2.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:file-static-0:5.39-12.1.el9_2.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:python3-file-magic-0:5.39-12.1.el9_2.tuxcare.els1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        },
        {
          "category": "impact",
          "details": "important",
          "product_ids": [
            "AlmaLinux-9.2:file-0:5.39-12.1.el9_2.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:file-devel-0:5.39-12.1.el9_2.tuxcare.els1.i686",
            "AlmaLinux-9.2:file-devel-0:5.39-12.1.el9_2.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:file-libs-0:5.39-12.1.el9_2.tuxcare.els1.i686",
            "AlmaLinux-9.2:file-libs-0:5.39-12.1.el9_2.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:file-static-0:5.39-12.1.el9_2.tuxcare.els1.x86_64",
            "AlmaLinux-9.2:python3-file-magic-0:5.39-12.1.el9_2.tuxcare.els1.noarch"
          ]
        }
      ]
    }
  ]
}