Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wxwf-h485-h4x8

Опубликовано: 14 мар. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.7

Описание

In Delinea PAM Secret Server 11.4, it is possible for an attacker (with Administrator access to the Secret Server machine) to read the following data from a memory dump: the decrypted master key, database credentials (when SQL Server Authentication is enabled), the encryption key of RabbitMQ queue messages, and session cookies.

In Delinea PAM Secret Server 11.4, it is possible for an attacker (with Administrator access to the Secret Server machine) to read the following data from a memory dump: the decrypted master key, database credentials (when SQL Server Authentication is enabled), the encryption key of RabbitMQ queue messages, and session cookies.

EPSS

Процентиль: 1%
0.0001
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-316

Связанные уязвимости

CVSS3: 6.7
nvd
почти 2 года назад

In Delinea PAM Secret Server 11.4, it is possible for an attacker (with Administrator access to the Secret Server machine) to read the following data from a memory dump: the decrypted master key, database credentials (when SQL Server Authentication is enabled), the encryption key of RabbitMQ queue messages, and session cookies.

EPSS

Процентиль: 1%
0.0001
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-316