Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5cjf-34qg-vxw7

Опубликовано: 14 авг. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

In processMessageImpl of ClientModeImpl.java, there is a possible credential disclosure in the TOFU flow due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

In processMessageImpl of ClientModeImpl.java, there is a possible credential disclosure in the TOFU flow due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

EPSS

Процентиль: 77%
0.01036
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 9.8
nvd
больше 2 лет назад

In processMessageImpl of ClientModeImpl.java, there is a possible credential disclosure in the TOFU flow due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

EPSS

Процентиль: 77%
0.01036
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-522