Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q5h7-2qmh-rxhr

Опубликовано: 06 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is enabled, it is possible for attackers to retrieve sensitive admin authentication keys which could result in a compromise of the entire product's API.

A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is enabled, it is possible for attackers to retrieve sensitive admin authentication keys which could result in a compromise of the entire product's API.

EPSS

Процентиль: 52%
0.00292
Низкий

7.5 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.5
redhat
около 1 года назад

A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is enabled, it is possible for attackers to retrieve sensitive admin authentication keys which could result in a compromise of the entire product's API.

CVSS3: 7.5
nvd
около 1 года назад

A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is enabled, it is possible for attackers to retrieve sensitive admin authentication keys which could result in a compromise of the entire product's API.

CVSS3: 7.5
debian
около 1 года назад

A disclosure of sensitive information flaw was found in foreman via th ...

EPSS

Процентиль: 52%
0.00292
Низкий

7.5 High

CVSS3

Дефекты

CWE-200