Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fh62-2wf5-r836

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.7

Описание

Nessus Agent versions 7.2.0 through 8.2.2 were found to inadvertently capture the IAM role security token on the local host during initial linking of the Nessus Agent when installed on an Amazon EC2 instance. This could allow a privileged attacker to obtain the token.

Nessus Agent versions 7.2.0 through 8.2.2 were found to inadvertently capture the IAM role security token on the local host during initial linking of the Nessus Agent when installed on an Amazon EC2 instance. This could allow a privileged attacker to obtain the token.

EPSS

Процентиль: 13%
0.00042
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 6.7
nvd
почти 5 лет назад

Nessus Agent versions 7.2.0 through 8.2.2 were found to inadvertently capture the IAM role security token on the local host during initial linking of the Nessus Agent when installed on an Amazon EC2 instance. This could allow a privileged attacker to obtain the token.

EPSS

Процентиль: 13%
0.00042
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-732