Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access control, which allows remote attackers to execute arbitrary RPC commands, and consequently write to arbitrary files, via POST requests to /transmission/rpc in conjunction with a DNS rebinding attack.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | Upgrade transmission | Feb 9, 2018 | Jan 15, 2018 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 15, 2018 |
| Debian | — | Upgrade transmission | Feb 19, 2019 | Jan 15, 2018 |
| Gentoo Linux | — | Upgrade net-p2p/transmission. | Jun 20, 2018 | Jan 15, 2018 |
| Oracle Solaris | — | Upgrade desktop/torrent/transmission to version 1.93-0.175.3.33.0.1.0 on Solaris 11.3 | Jun 18, 2018 | Jan 15, 2018 |
| Suse | — | Upgrade transmission-gtkUpgrade transmission-gtk-langUpgrade transmission-common | May 19, 2018 | Jan 15, 2018 |
| Ubuntu | — | Upgrade transmission | Jan 17, 2018 | Jan 15, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub