Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g9fp-4f3g-gqmr

Опубликовано: 24 июн. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

OrangeScrum version 2.0.11 allows an external attacker to remotely obtain AWS instance credentials. This is possible because the application does not properly validate the HTML content to be converted to PDF.

OrangeScrum version 2.0.11 allows an external attacker to remotely obtain AWS instance credentials. This is possible because the application does not properly validate the HTML content to be converted to PDF.

EPSS

Процентиль: 23%
0.00077
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.5
nvd
больше 2 лет назад

OrangeScrum version 2.0.11 allows an external attacker to remotely obtain AWS instance credentials. This is possible because the application does not properly validate the HTML content to be converted to PDF.

EPSS

Процентиль: 23%
0.00077
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-79