Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qhfj-6wg2-mmvj

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, file metadata information is disclosed to group members in the Elasticsearch result list despite them not having access to that artefact anymore.

In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, file metadata information is disclosed to group members in the Elasticsearch result list despite them not having access to that artefact anymore.

EPSS

Процентиль: 43%
0.00205
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 6 лет назад

In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, file metadata information is disclosed to group members in the Elasticsearch result list despite them not having access to that artefact anymore.

CVSS3: 4.3
nvd
почти 6 лет назад

In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, file metadata information is disclosed to group members in the Elasticsearch result list despite them not having access to that artefact anymore.

CVSS3: 4.3
debian
почти 6 лет назад

In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before ...

EPSS

Процентиль: 43%
0.00205
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200