Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hggv-mcp4-vxc5

Опубликовано: 12 мар. 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Improper Authentication in FreeTAKServer

FreeTAKServer is an open source, lightweight Server for connect TAK clients. An access control issue in the component /ManageRoute/postRoute of FreeTAKServer version 1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. There is currently no known workaround. This issue was fixed in version 1.9.8.5.

Пакеты

Наименование

FreeTAKServer

pip
Затронутые версииВерсия исправления

<= 1.9.8

1.9.8.5

EPSS

Процентиль: 83%
0.01847
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-287
CWE-306

Связанные уязвимости

CVSS3: 7.5
nvd
почти 4 года назад

An access control issue in the component /ManageRoute/postRoute of FreeTAKServer v1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users.

EPSS

Процентиль: 83%
0.01847
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-287
CWE-306