Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-14511

Опубликовано: 22 авг. 2019
Источник: debian

Описание

Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it exposed to the internet (unless filtered by a firewall or reconfigured to listen to 127.0.0.1 only).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
sphinxsearchfixed2.2.11-4package

Примечания

  • Issue is just with the default configuration, but can be easily reconfigured

  • to listen on localhost only. sphinxsearch will not be started automatically

  • and an admin needs first to create anyway a /etc/sphinxsearch/sphinx.conf

  • starting from a sample.

  • sphinxsearch should ideally update the defaults in sample configs to bind

  • listeners to localhost.

  • This is not treated as a vulnerability, subject to design choices for deployment

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it exposed to the internet (unless filtered by a firewall or reconfigured to listen to 127.0.0.1 only).

CVSS3: 7.5
nvd
больше 6 лет назад

Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it exposed to the internet (unless filtered by a firewall or reconfigured to listen to 127.0.0.1 only).

CVSS3: 7.5
github
больше 3 лет назад

Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it exposed to the internet (unless filtered by a firewall or reconfigured to listen to 127.0.0.1 only).