Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8fqw-xqvx-7f2j

Опубликовано: 12 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.5

Описание

Insertion of Sensitive Information into Log File (CWE-532) in the Gallagher Command Centre Alarm Transmitter feature could allow an authenticated Operator to view some security sensitive information to which they have not been granted access.

This issue affects: Command Centre Server 9.10 prior to 9.10.2149 (MR4), 9.00 prior to 9.00.2374 (MR5), 8.90 prior to 8.90.2356 (MR6), all versions of 8.80 and prior.

Insertion of Sensitive Information into Log File (CWE-532) in the Gallagher Command Centre Alarm Transmitter feature could allow an authenticated Operator to view some security sensitive information to which they have not been granted access.

This issue affects: Command Centre Server 9.10 prior to 9.10.2149 (MR4), 9.00 prior to 9.00.2374 (MR5), 8.90 prior to 8.90.2356 (MR6), all versions of 8.80 and prior.

EPSS

Процентиль: 38%
0.00166
Низкий

8.5 High

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 8.5
nvd
около 1 года назад

Insertion of Sensitive Information into Log File (CWE-532) in the Gallagher Command Centre Alarm Transmitter feature could allow an authenticated Operator to view some security sensitive information to which they have not been granted access. This issue affects: Command Centre Server 9.10 prior to 9.10.2149 (MR4), 9.00 prior to 9.00.2374 (MR5), 8.90 prior to 8.90.2356 (MR6), all versions of 8.80 and prior.

EPSS

Процентиль: 38%
0.00166
Низкий

8.5 High

CVSS3

Дефекты

CWE-532