Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vhqh-w8vh-h8h6

Опубликовано: 27 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.3

Описание

Xerox Workplace Suite stores tokens in session storage, which may expose them to potential access if a user's session is compromised. 

The patch for this vulnerability will be included in a future release of Workplace Suite, and customers will be notified through an update to the security bulletin.

Xerox Workplace Suite stores tokens in session storage, which may expose them to potential access if a user's session is compromised. 

The patch for this vulnerability will be included in a future release of Workplace Suite, and customers will be notified through an update to the security bulletin.

EPSS

Процентиль: 33%
0.00129
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-922

Связанные уязвимости

CVSS3: 6.5
nvd
около 1 года назад

Xerox Workplace Suite stores tokens in session storage, which may expose them to potential access if a user's session is compromised.  The patch for this vulnerability will be included in a future release of Workplace Suite, and customers will be notified through an update to the security bulletin.

CVSS3: 6.3
fstec
около 1 года назад

Уязвимость сервера управления печатью Xerox Workplace Suite, связанная с незащищенным хранением конфиденциальной информации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 33%
0.00129
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-922