Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fcjq-9fhq-v247

Опубликовано: 23 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

There is a broken access control vulnerability in the Maarch RM 2.8.3 solution. When accessing some specific document (pdf, email) from an archive, a preview is proposed by the application. This preview generates a URL including an md5 hash of the file accessed. The document's URL (https://{url}/tmp/{MD5 hash of the document}) is then accessible without authentication.

There is a broken access control vulnerability in the Maarch RM 2.8.3 solution. When accessing some specific document (pdf, email) from an archive, a preview is proposed by the application. This preview generates a URL including an md5 hash of the file accessed. The document's URL (https://{url}/tmp/{MD5 hash of the document}) is then accessible without authentication.

EPSS

Процентиль: 44%
0.00213
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 5.3
nvd
около 3 лет назад

There is a broken access control vulnerability in the Maarch RM 2.8.3 solution. When accessing some specific document (pdf, email) from an archive, a preview is proposed by the application. This preview generates a URL including an md5 hash of the file accessed. The document's URL (https://{url}/tmp/{MD5 hash of the document}) is then accessible without authentication.

EPSS

Процентиль: 44%
0.00213
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-287