CVE-2025-1395
8.2Codriapp Innovation and Software Technologies Inc · HeyGarson
A sensitive information disclosure vulnerability exists in the HeyGarson application, allowing unauthenticated attackers to perform fuzzing for application mapping through verbose error messages.
Executive summary
The HeyGarson application is vulnerable to information disclosure through improper error handling, which facilitates unauthorized application mapping by unauthenticated actors.
Vulnerability
This vulnerability, classified as CWE-209, stems from the generation of error messages containing sensitive technical details. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N) confirms that an unauthenticated attacker can exploit this remotely with low complexity.
Business impact
Successful exploitation allows an attacker to map the internal structure and configuration of the application, significantly lowering the barrier for subsequent, more targeted attacks. Given the high CVSS score of 8.2, this information leak could lead to unauthorized access to sensitive system metadata, potentially compromising the confidentiality and integrity of the underlying environment.
Remediation
Immediate Action: As the vendor has confirmed that this product is no longer supported, users should immediately sunset or decommission the HeyGarson application.
Proactive Monitoring: Monitor network traffic and server logs for unusual patterns of error codes or high volumes of requests originating from single IP addresses that indicate automated reconnaissance or fuzzing attempts.
Compensating Controls: Implement strict Web Application Firewall (WAF) rules to filter and normalize error responses, preventing sensitive system information from reaching the client side.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Due to the lack of vendor support and the critical nature of the information disclosure, the most effective remediation is the immediate removal of the HeyGarson product from the network. Organizations relying on this software should prioritize migrating to a supported alternative to ensure long-term security.
Sources
Originally found and disclosed by Şahnur Eren ALOĞLU, per the CVE Program record.