Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2gx6-qrpp-c4p3

Опубликовано: 29 нояб. 2024
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Ant-Media-Server vulnerable to Improper Output Neutralization for Logs

Ant-Media-Server v2.8.2 is affected by Improper Output Neutralization for Logs. The vulnerability stems from insufficient input sanitization in the logging mechanism. Without proper filtering or validation, user-controllable data, such as identifiers or other sensitive information, can be included in log entries without restrictions.

Пакеты

Наименование

io.antmedia:ant-media-server

maven
Затронутые версииВерсия исправления

< 2.9.0

2.9.0

EPSS

Процентиль: 23%
0.00077
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 7.5
nvd
около 1 года назад

Ant-Media-Serverv2.8.2 is affected by Improper Output Neutralization for Logs. The vulnerability stems from insufficient input sanitization in the logging mechanism. Without proper filtering or validation, user-controllable data, such as identifiers or other sensitive information, can be included in log entries without restrictions.

EPSS

Процентиль: 23%
0.00077
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-125