Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-73jx-2vf6-7ffj

Опубликовано: 06 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

This advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certain set of conditions, user passwords can be leaked in the Audit and System logs. The impact of this vulnerability is that the CVP user login passwords might be leaked to other authenticated users.

This advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certain set of conditions, user passwords can be leaked in the Audit and System logs. The impact of this vulnerability is that the CVP user login passwords might be leaked to other authenticated users.

EPSS

Процентиль: 16%
0.00049
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-200
CWE-532

Связанные уязвимости

CVSS3: 4
nvd
больше 3 лет назад

This advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certain set of conditions, user passwords can be leaked in the Audit and System logs. The impact of this vulnerability is that the CVP user login passwords might be leaked to other authenticated users.

EPSS

Процентиль: 16%
0.00049
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-200
CWE-532