{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-11222","assignerOrgId":"657f3255-0560-4aed-82e4-7f579ec6acfb","state":"PUBLISHED","assignerShortName":"LY-Corporation","dateReserved":"2025-10-01T01:03:38.026Z","datePublished":"2025-12-04T12:18:14.206Z","dateUpdated":"2025-12-04T14:41:14.531Z"},"containers":{"cna":{"affected":[{"vendor":"LINE Corporation","product":"Central Dogma","versions":[{"version":"0.77","status":"affected","versionType":"custom","lessThan":"0.78.0"}]}],"problemTypes":[{"descriptions":[{"lang":"en","description":"na"}]}],"descriptions":[{"lang":"en","value":"Central Dogma versions before 0.78.0 contain an Open Redirect vulnerability that allows attackers to redirect users to untrusted sites via specially crafted URLs, potentially facilitating phishing attacks and credential theft."}],"references":[{"url":"https://github.com/line/centraldogma/security/advisories/GHSA-4hr2-xf7w-jf76"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM","exploitCodeMaturity":"NOT_DEFINED","remediationLevel":"NOT_DEFINED","reportConfidence":"NOT_DEFINED","temporalScore":6.1,"temporalSeverity":"MEDIUM","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NETWORK","modifiedAttackComplexity":"LOW","modifiedPrivilegesRequired":"NONE","modifiedUserInteraction":"REQUIRED","modifiedScope":"CHANGED","modifiedConfidentialityImpact":"LOW","modifiedIntegrityImpact":"LOW","modifiedAvailabilityImpact":"NONE","environmentalScore":6.1,"environmentalSeverity":"MEDIUM"}}],"providerMetadata":{"orgId":"657f3255-0560-4aed-82e4-7f579ec6acfb","shortName":"LY-Corporation","dateUpdated":"2025-12-04T12:18:14.206Z"}},"adp":[{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-601","lang":"en","description":"CWE-601 URL Redirection to Untrusted Site ('Open Redirect')"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-12-04T14:41:10.607528Z","id":"CVE-2025-11222","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-12-04T14:41:14.531Z"}}]}}