Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wxfx-g5v8-gmxf

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

Cloud Foundry Bits Service, versions prior to 2.18.0, includes an information disclosure vulnerability. A remote malicious user may execute a timing attack to brute-force the signing key, allowing them complete read and write access to the the Bits Service storage.

Cloud Foundry Bits Service, versions prior to 2.18.0, includes an information disclosure vulnerability. A remote malicious user may execute a timing attack to brute-force the signing key, allowing them complete read and write access to the the Bits Service storage.

EPSS

Процентиль: 52%
0.00292
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 8.1
nvd
около 7 лет назад

Cloud Foundry Bits Service, versions prior to 2.18.0, includes an information disclosure vulnerability. A remote malicious user may execute a timing attack to brute-force the signing key, allowing them complete read and write access to the the Bits Service storage.

EPSS

Процентиль: 52%
0.00292
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-200