Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hjx4-ghxm-xpj2

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In tangro Business Workflow before 1.18.1, knowing an attachment ID, it is possible to download workitem attachments without being authenticated.

In tangro Business Workflow before 1.18.1, knowing an attachment ID, it is possible to download workitem attachments without being authenticated.

EPSS

Процентиль: 49%
0.00258
Низкий

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 5.3
nvd
около 5 лет назад

In tangro Business Workflow before 1.18.1, knowing an attachment ID, it is possible to download workitem attachments without being authenticated.

EPSS

Процентиль: 49%
0.00258
Низкий

Дефекты

CWE-639