Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-755x-c9g7-3hr7

Опубликовано: 15 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 5.3

Описание

evolution-api through 2.3.7 contains an incorrect array comparison in the metricsIPWhitelist middleware that always evaluates to false, allowing unauthenticated access to the /metrics endpoint. Attackers can bypass IP whitelist restrictions to access sensitive metrics disclosing server version, database client name, configured server URL, and WhatsApp instance details.

evolution-api through 2.3.7 contains an incorrect array comparison in the metricsIPWhitelist middleware that always evaluates to false, allowing unauthenticated access to the /metrics endpoint. Attackers can bypass IP whitelist restrictions to access sensitive metrics disclosing server version, database client name, configured server URL, and WhatsApp instance details.

EPSS

Процентиль: 27%
0.00337
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-697

Связанные уязвимости

CVSS3: 5.3
nvd
4 дня назад

evolution-api through 2.3.7 contains an incorrect array comparison in the metricsIPWhitelist middleware that always evaluates to false, allowing unauthenticated access to the /metrics endpoint. Attackers can bypass IP whitelist restrictions to access sensitive metrics disclosing server version, database client name, configured server URL, and WhatsApp instance details.

EPSS

Процентиль: 27%
0.00337
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-697