Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-37fx-2m8v-2x4j

Опубликовано: 03 авг. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 4

Описание

NVIDIA Omniverse Workstation Launcher for Windows and Linux contains a vulnerability in the authentication flow, where a user’s access token is displayed in the browser user's address bar. An attacker could use this token to impersonate the user to access launcher resources. A successful exploit of this vulnerability may lead to information disclosure.

NVIDIA Omniverse Workstation Launcher for Windows and Linux contains a vulnerability in the authentication flow, where a user’s access token is displayed in the browser user's address bar. An attacker could use this token to impersonate the user to access launcher resources. A successful exploit of this vulnerability may lead to information disclosure.

EPSS

Процентиль: 36%
0.00152
Низкий

4 Medium

CVSS3

Дефекты

CWE-598

Связанные уязвимости

CVSS3: 4
nvd
больше 2 лет назад

NVIDIA Omniverse Workstation Launcher for Windows and Linux contains a vulnerability in the authentication flow, where a user’s access token is displayed in the browser user's address bar. An attacker could use this token to impersonate the user to access launcher resources. A successful exploit of this vulnerability may lead to information disclosure.

CVSS3: 5.3
fstec
больше 2 лет назад

Уязвимость программного средства для управления доступом к платформе Omniverse NVIDIA Omniverse Workstation Launcher, связанная с раскрытием информации посредством строки запросов, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 36%
0.00152
Низкий

4 Medium

CVSS3

Дефекты

CWE-598