Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2019-0741

Опубликовано: 12 фев. 2019
Источник: msrc
EPSS Низкий

Описание

Azure IoT Java SDK Information Disclosure Vulnerability

An information disclosure vulnerability exists in the way Azure IoT Java SDK logs sensitive information. An attacker can exploit this vulnerability if a user has exposed the logs on the internet (or an attacker was able to get the logs) and can use this information to compromise the device.

This update addresses this vulnerability by not storing sensitive information in the logs.

FAQ

What type of information could be disclosed by this vulnerability?

The type of information that could be disclosed if an attacker successfully exploited this vulnerability is device information like resource ids, sas tokens, user properties, and other sensitive information.

Обновления

ПродуктСтатьяОбновление
Java SDK for Azure IoT

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

N/A

Older Software Release

Exploitation Less Likely

EPSS

Процентиль: 87%
0.03317
Низкий

Связанные уязвимости

CVSS3: 7.5
nvd
больше 6 лет назад

An information disclosure vulnerability exists in the way Azure IoT Java SDK logs sensitive information, aka 'Azure IoT Java SDK Information Disclosure Vulnerability'.

CVSS3: 7.5
github
больше 3 лет назад

An information disclosure vulnerability exists in the way Azure IoT Java SDK logs sensitive information, aka 'Azure IoT Java SDK Information Disclosure Vulnerability'.

EPSS

Процентиль: 87%
0.03317
Низкий