Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qp56-qj59-hjf8

Опубликовано: 01 дек. 2025
Источник: github
Github: Прошло ревью
CVSS4: 2.1
CVSS3: 4.3

Описание

NutzBoot vulnerable to information disclosure

A security flaw has been discovered in nutzam NutzBoot up to 2.6.0-SNAPSHOT. The impacted element is an unknown function of the file nutzboot-demo/nutzboot-demo-simple/nutzboot-demo-simple-web3j/src/main/java/io/nutz/demo/simple/module/EthModule.java of the component Ethereum Wallet Handler. Performing manipulation results in information disclosure. The attack may be initiated remotely. The exploit has been released to the public and may be exploited.

Пакеты

Наименование

org.nutz:nutzboot-parent

maven
Затронутые версииВерсия исправления

<= 2.6.0-SNAPSHOT

Отсутствует

EPSS

Процентиль: 10%
0.00034
Низкий

2.1 Low

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4.3
nvd
2 месяца назад

A security flaw has been discovered in nutzam NutzBoot up to 2.6.0-SNAPSHOT. The impacted element is an unknown function of the file nutzboot-demo/nutzboot-demo-simple/nutzboot-demo-simple-web3j/src/main/java/io/nutz/demo/simple/module/EthModule.java of the component Ethereum Wallet Handler. Performing manipulation results in information disclosure. The attack may be initiated remotely. The exploit has been released to the public and may be exploited.

EPSS

Процентиль: 10%
0.00034
Низкий

2.1 Low

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-200