Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2ccx-3vjx-pj7f

Опубликовано: 20 мар. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

In Progress MOVEit Transfer versions released before 2022.0.11 (14.0.11), 2022.1.12 (14.1.12), 2023.0.9 (15.0.9), 2023.1.4 (15.1.4), a logging bypass vulnerability has been discovered.  An authenticated user could manipulate a request to bypass the logging mechanism within the web application which results in user activity not being logged properly.

In Progress MOVEit Transfer versions released before 2022.0.11 (14.0.11), 2022.1.12 (14.1.12), 2023.0.9 (15.0.9), 2023.1.4 (15.1.4), a logging bypass vulnerability has been discovered.  An authenticated user could manipulate a request to bypass the logging mechanism within the web application which results in user activity not being logged properly.

EPSS

Процентиль: 26%
0.00089
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-778

Связанные уязвимости

CVSS3: 4.3
nvd
почти 2 года назад

In Progress MOVEit Transfer versions released before 2022.0.11 (14.0.11), 2022.1.12 (14.1.12), 2023.0.9 (15.0.9), 2023.1.4 (15.1.4), a logging bypass vulnerability has been discovered.  An authenticated user could manipulate a request to bypass the logging mechanism within the web application which results in user activity not being logged properly.

EPSS

Процентиль: 26%
0.00089
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-778