Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r3p9-xjh5-cp2m

Опубликовано: 17 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

There is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1 and below which could allow a remote, unauthenticated attacker to access an API that may induce Esri Portal for ArcGIS to read arbitrary URLs.

There is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1 and below which could allow a remote, unauthenticated attacker to access an API that may induce Esri Portal for ArcGIS to read arbitrary URLs.

EPSS

Процентиль: 75%
0.00864
Низкий

7.5 High

CVSS3

Дефекты

CWE-284
CWE-668

Связанные уязвимости

CVSS3: 7.5
nvd
больше 3 лет назад

There is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1 and below which could allow a remote, unauthenticated attacker to access an API that may induce Esri Portal for ArcGIS to read arbitrary URLs.

CVSS3: 7.5
fstec
больше 3 лет назад

Уязвимость веб-портала Portal for ArcGIS, связанная с недостатками контроля доступа, позволяющая нарушителю повысить свои привилегии в целевой системе

EPSS

Процентиль: 75%
0.00864
Низкий

7.5 High

CVSS3

Дефекты

CWE-284
CWE-668