Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4fh7-m2wx-6wfm

Опубликовано: 04 дек. 2024
Источник: github
Github: Прошло ревью
CVSS4: 2.9
CVSS3: 5.3

Описание

Firepad allows insecure document access

Firepad through 1.5.11 allows remote attackers, who have knowledge of a pad ID, to retrieve both the current text of a document and all content that has previously been pasted into the document. NOTE: in several similar products, this is the intentional behavior for anyone who knows the full document ID and corresponding URL. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Пакеты

Наименование

firepad

npm
Затронутые версииВерсия исправления

<= 1.5.11

Отсутствует

EPSS

Процентиль: 32%
0.00122
Низкий

2.9 Low

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-125
CWE-200

Связанные уязвимости

CVSS3: 5.3
nvd
около 1 года назад

Firepad through 1.5.11 allows remote attackers, who have knowledge of a pad ID, to retrieve both the current text of a document and all content that has previously been pasted into the document. NOTE: in several similar products, this is the intentional behavior for anyone who knows the full document ID and corresponding URL. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

EPSS

Процентиль: 32%
0.00122
Низкий

2.9 Low

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-125
CWE-200