Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-39289

Опубликовано: 07 окт. 2022
Источник: debian
EPSS Низкий

Описание

ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder API Exposes Database Log contents to user without privileges, allows insertion, modification, deletion of logs without System Privileges. Users are advised yo upgrade as soon as possible. Users unable to upgrade should disable database logging.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
zoneminderfixed1.36.31+dfsg1-1package

Примечания

  • https://github.com/ZoneMinder/zoneminder/commit/34ffd92bf123070cab6c83ad4cfe6297dd0ed0b4

  • https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-mpcx-3gvh-9488

  • Only supported for trusted users/behind auth, see README.debian.security

EPSS

Процентиль: 57%
0.00353
Низкий

Связанные уязвимости

CVSS3: 9.1
ubuntu
больше 3 лет назад

ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder API Exposes Database Log contents to user without privileges, allows insertion, modification, deletion of logs without System Privileges. Users are advised yo upgrade as soon as possible. Users unable to upgrade should disable database logging.

CVSS3: 9.1
nvd
больше 3 лет назад

ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder API Exposes Database Log contents to user without privileges, allows insertion, modification, deletion of logs without System Privileges. Users are advised yo upgrade as soon as possible. Users unable to upgrade should disable database logging.

EPSS

Процентиль: 57%
0.00353
Низкий