Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-258h-f687-4226

Опубликовано: 31 июл. 2024
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 4.4

Описание

PheonixAppAPI has visible Encoding Maps

Impact

This is a kind of moderate issue. The impact is not big for normal users but can be for users who want to secure their code/files/etc.

The issue is that the map of encoding/decoding languages are visible in code.

Patches

The Problem was patched in 0.2.5, so you should try to upgrade to the 0.2.5 version.

For 0.2.5 version users

Please run the post_install.py file inside the Scripts folder after downloading from pip.

Workarounds

There is a fix to this problem but it requires modifying the code. Modifying the code can lead to more issues.

References

There are currently no references to this problem.

NOTE: If you get a error regarding a function like -> get_key() or something like that, please re-run the file post_install.py inside Scripts folder

Пакеты

Наименование

PheonixAppAPI

pip
Затронутые версииВерсия исправления

< 0.2.5

0.2.5

EPSS

Процентиль: 19%
0.0006
Низкий

5.3 Medium

CVSS4

4.4 Medium

CVSS3

Дефекты

CWE-323

Связанные уязвимости

CVSS3: 4.4
nvd
больше 1 года назад

Pheonix App is a Python application designed to streamline various tasks, from managing files to playing mini-games. The issue is that the map of encoding/decoding languages are visible in code. The Problem was patched in 0.2.4.

EPSS

Процентиль: 19%
0.0006
Низкий

5.3 Medium

CVSS4

4.4 Medium

CVSS3

Дефекты

CWE-323