Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j2wh-jq5r-qm6f

Опубликовано: 14 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 2.3

Описание

An insertion of sensitive information into log file vulnerability [CWE-532] in FortiSIEM version 7.0.0, version 6.7.6 and below, version 6.6.3 and below, version 6.5.1 and below, version 6.4.2 and below, version 6.3.3 and below, version 6.2.1 and below, version 6.1.2 and below, version 5.4.0, version 5.3.3 and below may allow an authenticated user to view an encrypted ElasticSearch password via debug log files generated when FortiSIEM is configured with ElasticSearch Event Storage.

An insertion of sensitive information into log file vulnerability [CWE-532] in FortiSIEM version 7.0.0, version 6.7.6 and below, version 6.6.3 and below, version 6.5.1 and below, version 6.4.2 and below, version 6.3.3 and below, version 6.2.1 and below, version 6.1.2 and below, version 5.4.0, version 5.3.3 and below may allow an authenticated user to view an encrypted ElasticSearch password via debug log files generated when FortiSIEM is configured with ElasticSearch Event Storage.

EPSS

Процентиль: 16%
0.00053
Низкий

2.3 Low

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 2.3
nvd
около 2 лет назад

An insertion of sensitive information into log file vulnerability [CWE-532] in FortiSIEM version 7.0.0, version 6.7.6 and below, version 6.6.3 and below, version 6.5.1 and below, version 6.4.2 and below, version 6.3.3 and below, version 6.2.1 and below, version 6.1.2 and below, version 5.4.0, version 5.3.3 and below may allow an authenticated user to view an encrypted ElasticSearch password via debug log files generated when FortiSIEM is configured with ElasticSearch Event Storage.

CVSS3: 3.3
fstec
около 2 лет назад

Уязвимость системы управления безопасностью FortiSIEM, связанная с недостаточной защитой регистрационных данных, позволяющая нарушителю получить доступ к конфиденциальной информации

EPSS

Процентиль: 16%
0.00053
Низкий

2.3 Low

CVSS3

Дефекты

CWE-532