Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q949-6jcq-74v3

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A misconfiguration in Web-Sesame 2020.1.1.3375 allows an unauthenticated attacker to download the source code of the application, facilitating its comprehension (code review). Specifically, JavaScript source maps were inadvertently included in the production Webpack configuration. These maps contain sources used to generate the bundle, configuration settings (e.g., API keys), and developers' comments.

A misconfiguration in Web-Sesame 2020.1.1.3375 allows an unauthenticated attacker to download the source code of the application, facilitating its comprehension (code review). Specifically, JavaScript source maps were inadvertently included in the production Webpack configuration. These maps contain sources used to generate the bundle, configuration settings (e.g., API keys), and developers' comments.

EPSS

Процентиль: 72%
0.00704
Низкий

Связанные уязвимости

CVSS3: 5.3
nvd
около 5 лет назад

A misconfiguration in Web-Sesame 2020.1.1.3375 allows an unauthenticated attacker to download the source code of the application, facilitating its comprehension (code review). Specifically, JavaScript source maps were inadvertently included in the production Webpack configuration. These maps contain sources used to generate the bundle, configuration settings (e.g., API keys), and developers' comments.

EPSS

Процентиль: 72%
0.00704
Низкий