Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vxmf-fxwp-m3ww

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can make unauthorized MySQL queries against the Orchestrator database using the /sqlExecution REST API, which had been used for internal testing.

In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can make unauthorized MySQL queries against the Orchestrator database using the /sqlExecution REST API, which had been used for internal testing.

EPSS

Процентиль: 79%
0.01324
Низкий

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.6
nvd
больше 5 лет назад

In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can make unauthorized MySQL queries against the Orchestrator database using the /sqlExecution REST API, which had been used for internal testing.

EPSS

Процентиль: 79%
0.01324
Низкий

Дефекты

CWE-22