Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-07230

Опубликовано: 18 мар. 2026
Источник: fstec
CVSS3: 8.1
CVSS2: 9.4
EPSS Низкий

Описание

Уязвимость прикладного программного интерфейса инструмента мониторинга Glances связана с использованием недоверенного файла междоменной политики. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, получить несанкционированный доступ к защищаемой информации

Вендор

ООО «Ред Софт»
Nicolas Hennion

Наименование ПО

РЕД ОС
Glances

Версия ПО

8.0 (РЕД ОС)
до 4.5.3 (Glances)

Тип ПО

Операционная система
Прикладное ПО информационных систем

Операционные системы и аппаратные платформы

ООО «Ред Софт» РЕД ОС 8.0

Уровень опасности уязвимости

Высокий уровень опасности (базовая оценка CVSS 2.0 составляет 9,4)
Высокий уровень опасности (базовая оценка CVSS 3.1 составляет 8,1)

Возможные меры по устранению уязвимости

Использование рекомендаций:
https://github.com/nicolargo/glances
https://github.com/nicolargo/glances/commit/4465169b71d93991f1e49740fe02428291099832
https://github.com/nicolargo/glances/releases/tag/v4.5.2
https://github.com/nicolargo/glances/security/advisories/GHSA-9jfm-9rc6-2hfq
Для Ред ОС:
https://redos.red-soft.ru/search/?iblock_id=24&q=CVE-2026-32610

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 26%
0.00339
Низкий

8.1 High

CVSS3

9.4 Critical

CVSS2

Связанные уязвимости

CVSS3: 8.1
ubuntu
5 месяцев назад

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, the Glances REST API web server ships with a default CORS configuration that sets `allow_origins=["*"]` combined with `allow_credentials=True`. When both of these options are enabled together, Starlette's `CORSMiddleware` reflects the requesting `Origin` header value in the `Access-Control-Allow-Origin` response header instead of returning the literal `*` wildcard. This effectively grants any website the ability to make credentialed cross-origin API requests to the Glances server, enabling cross-site data theft of system monitoring information, configuration secrets, and command line arguments from any user who has an active browser session with a Glances instance. Version 4.5.2 fixes the issue.

CVSS3: 8.1
nvd
5 месяцев назад

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, the Glances REST API web server ships with a default CORS configuration that sets `allow_origins=["*"]` combined with `allow_credentials=True`. When both of these options are enabled together, Starlette's `CORSMiddleware` reflects the requesting `Origin` header value in the `Access-Control-Allow-Origin` response header instead of returning the literal `*` wildcard. This effectively grants any website the ability to make credentialed cross-origin API requests to the Glances server, enabling cross-site data theft of system monitoring information, configuration secrets, and command line arguments from any user who has an active browser session with a Glances instance. Version 4.5.2 fixes the issue.

CVSS3: 8.1
debian
5 месяцев назад

Glances is an open-source system cross-platform monitoring tool. Prior ...

CVSS3: 8.1
github
5 месяцев назад

Glances's Default CORS Configuration Allows Cross-Origin Credential Theft

EPSS

Процентиль: 26%
0.00339
Низкий

8.1 High

CVSS3

9.4 Critical

CVSS2