Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qg95-6496-m556

Опубликовано: 12 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

Insertion of sensitive information in the centralized (Grafana) logging system in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate other users in web management and the REST API by reading JWT tokens from logs (as a Granafa authenticated user) or from the Loki REST API without authentication.

Insertion of sensitive information in the centralized (Grafana) logging system in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate other users in web management and the REST API by reading JWT tokens from logs (as a Granafa authenticated user) or from the Loki REST API without authentication.

EPSS

Процентиль: 29%
0.00103
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 9.1
nvd
около 2 лет назад

Insertion of sensitive information in the centralized (Grafana) logging system in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate other users in web management and the REST API by reading JWT tokens from logs (as a Granafa authenticated user) or from the Loki REST API without authentication.

EPSS

Процентиль: 29%
0.00103
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-532