Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jqrr-cj4q-x8m4

Опубликовано: 30 авг. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The controller responsible for setting the logging level does not include any authorization checks to ensure the user is authenticated. This can be seen by noting that it extends Controller rather than AuthenticatedController and includes no further checks. This issue affects YugabyteDB Anywhere: from 2.0.0 through 2.17.3

The controller responsible for setting the logging level does not include any authorization checks to ensure the user is authenticated. This can be seen by noting that it extends Controller rather than AuthenticatedController and includes no further checks. This issue affects YugabyteDB Anywhere: from 2.0.0 through 2.17.3

EPSS

Процентиль: 22%
0.00074
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 6.5
nvd
больше 2 лет назад

The controller responsible for setting the logging level does not include any authorization checks to ensure the user is authenticated. This can be seen by noting that it extends Controller rather than AuthenticatedController and includes no further checks. This issue affects YugabyteDB Anywhere: from 2.0.0 through 2.17.3

EPSS

Процентиль: 22%
0.00074
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-284