Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-66qf-8j2h-9xmq

Опубликовано: 29 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

A valid, authenticated administrative user can query a web interface API to reveal the configured LDAP client password used by XCC to authenticate to an external LDAP server in certain configurations. There is no exposure where no LDAP client password is configured

A valid, authenticated administrative user can query a web interface API to reveal the configured LDAP client password used by XCC to authenticate to an external LDAP server in certain configurations. There is no exposure where no LDAP client password is configured

EPSS

Процентиль: 33%
0.00134
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 4.9
nvd
почти 3 года назад

A valid, authenticated administrative user can query a web interface API to reveal the configured LDAP client password used by XCC to authenticate to an external LDAP server in certain configurations. There is no exposure where no LDAP client password is configured

EPSS

Процентиль: 33%
0.00134
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-522