Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xx5w-cqxh-w2m4

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

Cloud Foundry Bits Service Release, versions prior to 2.14.0, uses an insecure hashing algorithm to sign URLs. A remote malicious user may obtain a signed URL and extract the signing key, allowing them complete read and write access to the the Bits Service storage.

Cloud Foundry Bits Service Release, versions prior to 2.14.0, uses an insecure hashing algorithm to sign URLs. A remote malicious user may obtain a signed URL and extract the signing key, allowing them complete read and write access to the the Bits Service storage.

EPSS

Процентиль: 62%
0.00438
Низкий

8.1 High

CVSS3

Дефекты

CWE-326

Связанные уязвимости

CVSS3: 8.1
nvd
почти 7 лет назад

Cloud Foundry Bits Service Release, versions prior to 2.14.0, uses an insecure hashing algorithm to sign URLs. A remote malicious user may obtain a signed URL and extract the signing key, allowing them complete read and write access to the the Bits Service storage.

EPSS

Процентиль: 62%
0.00438
Низкий

8.1 High

CVSS3

Дефекты

CWE-326