Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access control, which allows remote attackers to execute arbitrary RPC commands, and consequently write to arbitrary files, via POST requests to /transmission/rpc in conjunction with a DNS rebinding attack.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | amazon-linux-upgrade-transmission | Feb 9, 2018 | Jan 15, 2018 |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Jan 15, 2018 | |
| Debian | debian-upgrade-transmission | Feb 19, 2019 | Jan 15, 2018 | |
| Gentoo Linux | gentoo-linux-upgrade-net-p2p-transmission | Jun 20, 2018 | Jan 15, 2018 | |
| Oracle Solaris | oracle-solaris-11-3-upgrade-desktop-torrent-transmission-1-93-0-175-3-33-0-1-0 | Jun 18, 2018 | Jan 15, 2018 | |
| Suse | — | suse-upgrade-transmission-commonsuse-upgrade-transmission-gtksuse-upgrade-transmission-gtk-lang | May 19, 2018 | Jan 15, 2018 |
| Ubuntu | ubuntu-upgrade-transmission | Jan 17, 2018 | Jan 15, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub