Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fvq4-c84w-q2rx

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

OpenAsset Digital Asset Management (DAM) 12.0.19 and earlier failed to implement access controls on /Stream/ProjectsCSV endpoint, allowing unauthenticated attackers to gain access to potentially sensitive project information stored by the application.

OpenAsset Digital Asset Management (DAM) 12.0.19 and earlier failed to implement access controls on /Stream/ProjectsCSV endpoint, allowing unauthenticated attackers to gain access to potentially sensitive project information stored by the application.

EPSS

Процентиль: 76%
0.00945
Низкий

Дефекты

CWE-1236

Связанные уязвимости

CVSS3: 5.3
nvd
около 5 лет назад

OpenAsset Digital Asset Management (DAM) 12.0.19 and earlier failed to implement access controls on /Stream/ProjectsCSV endpoint, allowing unauthenticated attackers to gain access to potentially sensitive project information stored by the application.

EPSS

Процентиль: 76%
0.00945
Низкий

Дефекты

CWE-1236