Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cfhp-p6xr-24g5

Опубликовано: 20 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious client or an attacker with a targeted RPC request to view the information that is part of the disclosed path.

A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious client or an attacker with a targeted RPC request to view the information that is part of the disclosed path.

EPSS

Процентиль: 82%
0.01859
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-201

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 2 лет назад

A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious client or an attacker with a targeted RPC request to view the information that is part of the disclosed path.

CVSS3: 5.3
redhat
около 2 лет назад

A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious client or an attacker with a targeted RPC request to view the information that is part of the disclosed path.

CVSS3: 5.3
nvd
около 2 лет назад

A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious client or an attacker with a targeted RPC request to view the information that is part of the disclosed path.

CVSS3: 5.3
debian
около 2 лет назад

A path disclosure vulnerability was found in Samba. As part of the Spo ...

CVSS3: 5.3
fstec
около 2 лет назад

Уязвимость пакета программ сетевого взаимодействия Samba, связанная с раскрытием информации, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 82%
0.01859
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-201