Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-89ff-5hgp-6w8j

Опубликовано: 26 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The App Settings (/admin/app) page in GROWI versions prior to v6.0.6 stores sensitive information in cleartext form. As a result, the Secret access key for external service may be obtained by an attacker who can access the App Settings page.

The App Settings (/admin/app) page in GROWI versions prior to v6.0.6 stores sensitive information in cleartext form. As a result, the Secret access key for external service may be obtained by an attacker who can access the App Settings page.

EPSS

Процентиль: 64%
0.0046
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-312

Связанные уязвимости

CVSS3: 6.5
nvd
около 2 лет назад

The App Settings (/admin/app) page in GROWI versions prior to v6.0.6 stores sensitive information in cleartext form. As a result, the Secret access key for external service may be obtained by an attacker who can access the App Settings page.

EPSS

Процентиль: 64%
0.0046
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-312