Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2894-qcqf-g23g

Опубликовано: 03 окт. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

asyncua Improper Authentication vulnerability

Versions of the package asyncua before 0.9.96 are vulnerable to Improper Authentication such that it is possible to access Address Space without encryption and authentication.

Note:

This issue is a result of missing checks for services that require an active session.

Пакеты

Наименование

asyncua

pip
Затронутые версииВерсия исправления

< 0.9.96

0.9.96

EPSS

Процентиль: 38%
0.00161
Низкий

7.5 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 2 лет назад

Versions of the package asyncua before 0.9.96 are vulnerable to Improper Authentication such that it is possible to access Address Space without encryption and authentication. **Note:** This issue is a result of missing checks for services that require an active session.

CVSS3: 6.5
nvd
около 2 лет назад

Versions of the package asyncua before 0.9.96 are vulnerable to Improper Authentication such that it is possible to access Address Space without encryption and authentication. **Note:** This issue is a result of missing checks for services that require an active session.

EPSS

Процентиль: 38%
0.00161
Низкий

7.5 High

CVSS3

Дефекты

CWE-287