CVE-2025-30038
Description
The vulnerability consists of a session ID leak when saving a file downloaded from CGM CLININET. The identifier is exposed through a built-in Windows security feature that stores additional metadata in an NTFS alternate data stream (ADS) for all files downloaded from potentially untrusted sources.
Is your site exposed to CVE-2025-30038?
Run a free security scan — no signup, results in seconds.
Weakness Type (CWE)
References
Other References
Frequently Asked Questions
What is CVE-2025-30038? +
How do I check if I'm vulnerable to CVE-2025-30038? +
Related Vulnerabilities
In lunary-ai/lunary version v1.4.29, the GET /projects API endpoint exposes both public and private API keys for all projects to …
The users endpoint in the groov View API returns a list of all users and associated metadata including their API …
Information disclosure while accessing and modifying the PIB file of a remote device via powerline.
In berriai/litellm version v1.52.1, an issue in proxy_server.py causes the leakage of Langfuse API keys when an error occurs while …
Dell NativeEdge, version(s) 2.1.0.0, contain(s) an Exposure of Sensitive Information Through Metadata vulnerability. An unauthenticated attacker with remote access could …
Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access