Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wmhc-qw7c-4774

Опубликовано: 19 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

An observable response discrepancy in the Gallagher Command Centre RESTAPI allows an insufficiently-privileged user to infer the presence of items that would not otherwise be viewable.

This issue affects: Gallagher Command Centre 8.70 prior to vEL8.70.1787 (MR2), 8.60 prior to vEL8.60.2039 (MR4), all version of 8.50 and prior.

An observable response discrepancy in the Gallagher Command Centre RESTAPI allows an insufficiently-privileged user to infer the presence of items that would not otherwise be viewable.

This issue affects: Gallagher Command Centre 8.70 prior to vEL8.70.1787 (MR2), 8.60 prior to vEL8.60.2039 (MR4), all version of 8.50 and prior.

EPSS

Процентиль: 38%
0.00168
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-203
CWE-204

Связанные уязвимости

CVSS3: 4.3
nvd
около 2 лет назад

An observable response discrepancy in the Gallagher Command Centre RESTAPI allows an insufficiently-privileged user to infer the presence of items that would not otherwise be viewable. This issue affects: Gallagher Command Centre 8.70 prior to vEL8.70.1787 (MR2), 8.60 prior to vEL8.60.2039 (MR4), all version of 8.50 and prior.

EPSS

Процентиль: 38%
0.00168
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-203
CWE-204