Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g7p8-r2ch-4rmf

Опубликовано: 17 дек. 2021
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Malicious Atomix node queries expose sensitive information

An issue in Atomix v3.1.5 allows attackers to access sensitive information when a malicious Atomix node queries distributed variable primitives which contain the entire primitive lists that ONOS nodes use to share important states.

Пакеты

Наименование

io.atomix:atomix

maven
Затронутые версииВерсия исправления

<= 3.1.5

Отсутствует

EPSS

Процентиль: 52%
0.00288
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-668

Связанные уязвимости

CVSS3: 6.5
redhat
около 4 лет назад

An issue in Atomix v3.1.5 allows attackers to access sensitive information when a malicious Atomix node queries distributed variable primitives which contain the entire primitive lists that ONOS nodes use to share important states.

CVSS3: 6.5
nvd
около 4 лет назад

An issue in Atomix v3.1.5 allows attackers to access sensitive information when a malicious Atomix node queries distributed variable primitives which contain the entire primitive lists that ONOS nodes use to share important states.

EPSS

Процентиль: 52%
0.00288
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-668