{"id":"CVE-2025-60949","summary":"Census CSWeb leaked configuration files","details":"Census CSWeb 8.0.1 allows \"app/config\" to be reachable via HTTP in some deployments. A remote, unauthenticated attacker could send requests to configuration files and obtain leaked secrets. Fixed in 8.1.0 alpha.","modified":"2026-08-12T03:51:13.671402350Z","published":"2026-03-23T21:00:55.751Z","database_specific":{"cna_assigner":"cisa-cg","cwe_ids":["CWE-200"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/60xxx/CVE-2025-60949.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"8.0.1"},{"fixed":"8.1.0 alpha"}]}]},"references":[{"type":"WEB","url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-082-01.json"},{"type":"WEB","url":"https://www.cve.org/CVERecord?id=CVE-2025-60949"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/60xxx/CVE-2025-60949.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-60949"},{"type":"FIX","url":"https://github.com/csprousers/csweb/commit/eba0b59a243390a1a4f9524cce6dbc0314bf0d91"},{"type":"PACKAGE","url":"https://github.com/hx381/cspro-exploits"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/csprousers/csweb","events":[{"introduced":"02a03dd6247f1c79a0437acf123955beed607238"},{"fixed":"eba0b59a243390a1a4f9524cce6dbc0314bf0d91"}],"database_specific":{"extracted_events":[{"introduced":"8.0.1"},{"last_affected":"8.0.1"}],"source":["CPE_STRING","REFERENCES"],"cpe":"cpe:2.3:a:csprousers:csweb:8.0.1:*:*:*:*:*:*:*"}}],"versions":["8.0.1","v8.0.1-2024-03-19"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-60949.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}