Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4gv5-mmhv-5c45

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SICK Package Analytics software up to and including version V04.0.0 are vulnerable to an authentication bypass by directly interfacing with the REST API. An attacker can send unauthorized requests, bypass current authentication controls presented by the application and could potentially write files without authentication.

SICK Package Analytics software up to and including version V04.0.0 are vulnerable to an authentication bypass by directly interfacing with the REST API. An attacker can send unauthorized requests, bypass current authentication controls presented by the application and could potentially write files without authentication.

EPSS

Процентиль: 62%
0.00431
Низкий

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.8
nvd
больше 5 лет назад

SICK Package Analytics software up to and including version V04.0.0 are vulnerable to an authentication bypass by directly interfacing with the REST API. An attacker can send unauthorized requests, bypass current authentication controls presented by the application and could potentially write files without authentication.

EPSS

Процентиль: 62%
0.00431
Низкий

Дефекты

CWE-287