Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5xq4-757g-rwc5

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A vulnerability in Arista’s CloudVision Portal (CVP) prior to 2020.2 allows users with “read-only” or greater access rights to the Configlet Management module to download files not intended for access, located on the CVP server, by accessing a specific API.

A vulnerability in Arista’s CloudVision Portal (CVP) prior to 2020.2 allows users with “read-only” or greater access rights to the Configlet Management module to download files not intended for access, located on the CVP server, by accessing a specific API.

EPSS

Процентиль: 44%
0.00212
Низкий

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 6.5
nvd
больше 5 лет назад

A vulnerability in Arista’s CloudVision Portal (CVP) prior to 2020.2 allows users with “read-only” or greater access rights to the Configlet Management module to download files not intended for access, located on the CVP server, by accessing a specific API.

EPSS

Процентиль: 44%
0.00212
Низкий

Дефекты

CWE-287