Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mpgx-6896-6pg4

Опубликовано: 27 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7.3

Описание

The vulnerability consists of a session ID leak when saving a file downloaded from CGM CLININET. The identifier is exposed through a built-in Windows security feature that stores additional metadata in an NTFS alternate data stream (ADS) for all files downloaded from potentially untrusted sources.

The vulnerability consists of a session ID leak when saving a file downloaded from CGM CLININET. The identifier is exposed through a built-in Windows security feature that stores additional metadata in an NTFS alternate data stream (ADS) for all files downloaded from potentially untrusted sources.

EPSS

Процентиль: 7%
0.00027
Низкий

7.3 High

CVSS4

Дефекты

CWE-1230

Связанные уязвимости

nvd
5 месяцев назад

The vulnerability consists of a session ID leak when saving a file downloaded from CGM CLININET. The identifier is exposed through a built-in Windows security feature that stores additional metadata in an NTFS alternate data stream (ADS) for all files downloaded from potentially untrusted sources.

EPSS

Процентиль: 7%
0.00027
Низкий

7.3 High

CVSS4

Дефекты

CWE-1230