{"id":"AZL-62429","summary":"CVE-2025-27792 affecting package opal 3.10.11-13","details":"Opal is OBiBa’s core database application for biobanks or epidemiological studies. Prior to version 5.1.1, the protections against cross-site request forgery (CSRF) were insufficient application-wide. The referrer header is checked, and if it is invalid, the server returns 403. However, the referrer header can be dropped from CSRF requests using `\u003cmeta name=\"referrer\" content=\"never\"\u003e`, effectively bypassing this protection. Version 5.1.1 contains a patch for the issue.","modified":"2026-04-21T04:32:02.394961Z","published":"2025-03-11T22:15:13Z","upstream":["CVE-2025-27792"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-27792"}],"affected":[{"package":{"name":"opal","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/opal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"3.10.11-13"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-62429.json"}}],"schema_version":"1.7.5"}