Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r25x-6f4h-78mr

Опубликовано: 22 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 4.3

Описание

An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessions aggregation stage. This information is normally restricted to users with cluster-level administrative privileges, and includes active session identifiers, associated usernames, and activity timestamps.

An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessions aggregation stage. This information is normally restricted to users with cluster-level administrative privileges, and includes active session identifiers, associated usernames, and activity timestamps.

EPSS

Процентиль: 20%
0.00277
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 1 месяца назад

An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessions aggregation stage. This information is normally restricted to users with cluster-level administrative privileges, and includes active session identifiers, associated usernames, and activity timestamps.

CVSS3: 4.3
nvd
около 1 месяца назад

An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessions aggregation stage. This information is normally restricted to users with cluster-level administrative privileges, and includes active session identifiers, associated usernames, and activity timestamps.

CVSS3: 4.3
debian
около 1 месяца назад

An authenticated user may be able to view session metadata belonging t ...

EPSS

Процентиль: 20%
0.00277
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-863