Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4f5w-327f-jw8g

Опубликовано: 21 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.1

Описание

An Improper Authorization vulnerability was identified in the EOL OVA based connect component which is deployed for installation purposes in the customer internal network. Under certain conditions, this could allow a bad actor to gain unauthorized access to the local db containing weakly hashed credentials of the installer. This EOL component was deprecated in September 2023 with end of support extended till January 2024.

An Improper Authorization vulnerability was identified in the EOL OVA based connect component which is deployed for installation purposes in the customer internal network. Under certain conditions, this could allow a bad actor to gain unauthorized access to the local db containing weakly hashed credentials of the installer. This EOL component was deprecated in September 2023 with end of support extended till January 2024.

EPSS

Процентиль: 4%
0.00018
Низкий

6.1 Medium

CVSS4

Дефекты

CWE-327

Связанные уязвимости

nvd
10 месяцев назад

An Improper Authorization vulnerability was identified in the EOL OVA based connect component which is deployed for installation purposes in the customer internal network. Under certain conditions, this could allow a bad actor to gain unauthorized access to the local db containing weakly hashed credentials of the installer. This EOL component was deprecated in September 2023 with end of support extended till January 2024.

EPSS

Процентиль: 4%
0.00018
Низкий

6.1 Medium

CVSS4

Дефекты

CWE-327