Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-48j5-grh5-3f4f

Опубликовано: 29 мар. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

Coverity versions prior to 2023.3.2 are vulnerable to forced browsing, which exposes authenticated resources to unauthorized actors. The root cause of this vulnerability is an insecurely configured servlet mapping for the underlying Apache Tomcat server. As a result, the downloads directory and its contents are accessible. 5.9 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L/E:P/RL:O/RC:C)

Coverity versions prior to 2023.3.2 are vulnerable to forced browsing, which exposes authenticated resources to unauthorized actors. The root cause of this vulnerability is an insecurely configured servlet mapping for the underlying Apache Tomcat server. As a result, the downloads directory and its contents are accessible. 5.9 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L/E:P/RL:O/RC:C)

EPSS

Процентиль: 33%
0.00131
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-425

Связанные уязвимости

CVSS3: 6.5
nvd
почти 3 года назад

Coverity versions prior to 2023.3.2 are vulnerable to forced browsing, which exposes authenticated resources to unauthorized actors. The root cause of this vulnerability is an insecurely configured servlet mapping for the underlying Apache Tomcat server. As a result, the downloads directory and its contents are accessible. 5.9 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L/E:P/RL:O/RC:C)

EPSS

Процентиль: 33%
0.00131
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-425