Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-10159

Опубликовано: 14 июн. 2019
Источник: nvd
CVSS3: 4.3
CVSS3: 4.3
CVSS2: 4
EPSS Низкий

Описание

cfme-gemset versions 5.10.4.3 and below, 5.9.9.3 and below are vulnerable to a data leak, due to an improper authorization in the migration log controller. An attacker with access to an unprivileged user can access all VM migration logs available.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:cfme-gemset:*:*:*:*:*:*:*:*
Версия от 5.9.0.22 (включая) до 5.9.9.3 (включая)
cpe:2.3:a:redhat:cfme-gemset:*:*:*:*:*:*:*:*
Версия от 5.10.0.33 (включая) до 5.10.4.3 (включая)
Конфигурация 2
cpe:2.3:a:redhat:cloudforms:4.7:*:*:*:*:*:*:*

EPSS

Процентиль: 44%
0.00215
Низкий

4.3 Medium

CVSS3

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-285
NVD-CWE-Other

Связанные уязвимости

CVSS3: 4.3
redhat
больше 6 лет назад

cfme-gemset versions 5.10.4.3 and below, 5.9.9.3 and below are vulnerable to a data leak, due to an improper authorization in the migration log controller. An attacker with access to an unprivileged user can access all VM migration logs available.

CVSS3: 4.3
github
больше 3 лет назад

cfme-gemset versions 5.10.4.3 and below, 5.9.9.3 and below are vulnerable to a data leak, due to an improper authorization in the migration log controller. An attacker with access to an unprivileged user can access all VM migration logs available.

EPSS

Процентиль: 44%
0.00215
Низкий

4.3 Medium

CVSS3

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-285
NVD-CWE-Other