CVE-2025-58366 | InseeFrLab onyxia up to 4.8.x Setting /public/catalogs insufficiently protected credentials (GHSA-m773-6vm8-8x6q / EUVD-2025-27163)
A vulnerability was found in InseeFrLab onyxia up to 4.8.x. It has been declared as critical. Affected by this issue is some unknown functionality of the file /public/catalogs of the component Setting Handler. Executing manipulation can lead to insufficiently protected credentials.
This vulnerability is tracked as CVE-2025-58366. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.