Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gqf4-w7p4-pm73

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) is vulnerable to Information Leakage, because of improper error handling with stack traces, as demonstrated by discovering a full pathname upon a 500 Internal Server Error via the api2/swis/query?lang=en-us&swAlertOnError=false query parameter.

SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) is vulnerable to Information Leakage, because of improper error handling with stack traces, as demonstrated by discovering a full pathname upon a 500 Internal Server Error via the api2/swis/query?lang=en-us&swAlertOnError=false query parameter.

EPSS

Процентиль: 45%
0.00223
Низкий

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.5
nvd
почти 6 лет назад

SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) is vulnerable to Information Leakage, because of improper error handling with stack traces, as demonstrated by discovering a full pathname upon a 500 Internal Server Error via the api2/swis/query?lang=en-us&swAlertOnError=false query parameter.

EPSS

Процентиль: 45%
0.00223
Низкий

Дефекты

CWE-200