Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-277v-gwfr-hmpj

Опубликовано: 11 окт. 2019
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

Missing Authentication for Critical Function in LibreNMS

An issue was discovered in LibreNMS through 1.47. A number of scripts import the Authentication libraries, but do not enforce an actual authentication check. Several of these scripts disclose information or expose functions that are of a sensitive nature and are not expected to be publicly accessible.

Пакеты

Наименование

librenms/librenms

composer
Затронутые версииВерсия исправления

< 1.50.1

1.50.1

EPSS

Процентиль: 0%
0.00004
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 9.1
nvd
около 6 лет назад

An issue was discovered in LibreNMS through 1.47. A number of scripts import the Authentication libraries, but do not enforce an actual authentication check. Several of these scripts disclose information or expose functions that are of a sensitive nature and are not expected to be publicly accessible.

EPSS

Процентиль: 0%
0.00004
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-306