Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9x36-c74v-fgr6

Опубликовано: 25 сент. 2025
Источник: github
Github: Прошло ревью
CVSS4: 5.5
CVSS3: 5.3

Описание

ml-logger file handler allows reading arbitrary files

A security flaw has been discovered in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected by this issue is the function stream_handler of the file ml_logger/server.py of the component File Handler. Performing manipulation of the argument key results in information disclosure. The attack can be initiated remotely. The exploit has been released to the public and may be exploited. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.

Пакеты

Наименование

ml-logger

pip
Затронутые версииВерсия исправления

<= 0.10.36

Отсутствует

EPSS

Процентиль: 14%
0.00044
Низкий

5.5 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.3
nvd
4 месяца назад

A security flaw has been discovered in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected by this issue is the function stream_handler of the file ml_logger/server.py of the component File Handler. Performing manipulation of the argument key results in information disclosure. The attack can be initiated remotely. The exploit has been released to the public and may be exploited. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.

EPSS

Процентиль: 14%
0.00044
Низкий

5.5 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-200