Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5wpq-pww3-r4mv

Опубликовано: 13 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Keyfactor SignServer before 7.3.1 has Incorrect Access Control, issue 3 of 3.

Keyfactor SignServer before 7.3.1 has Incorrect Access Control, issue 3 of 3.

EPSS

Процентиль: 18%
0.00056
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 6.5
nvd
3 месяца назад

A class name enumeration was found in Keyfactor SignServer versions prior to 7.3.2. Setting any chosen class name to any of the properties requiring a class path and the provided class is not expected to return different errors if the class exists in deployment or not. This returns information about the classes loaded in the application or not to the clientside.

EPSS

Процентиль: 18%
0.00056
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-284