Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-1693

Опубликовано: 17 фев. 2020
Источник: nvd
CVSS3: 8.6
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

A flaw was found in Spacewalk up to version 2.9 where it was vulnerable to XML internal entity attacks via the /rpc/api endpoint. An unauthenticated remote attacker could use this flaw to retrieve the content of certain files and trigger a denial of service, or in certain circumstances, execute arbitrary code on the Spacewalk server.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:spacewalk:*:*:*:*:*:*:*:*
Версия до 2.9 (исключая)

EPSS

Процентиль: 91%
0.07131
Низкий

8.6 High

CVSS3

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-611
CWE-611

Связанные уязвимости

CVSS3: 8.6
redhat
почти 6 лет назад

A flaw was found in Spacewalk up to version 2.9 where it was vulnerable to XML internal entity attacks via the /rpc/api endpoint. An unauthenticated remote attacker could use this flaw to retrieve the content of certain files and trigger a denial of service, or in certain circumstances, execute arbitrary code on the Spacewalk server.

github
больше 3 лет назад

A flaw was found in Spacewalk up to version 2.9 where it was vulnerable to XML internal entity attacks via the /rpc/api endpoint. An unauthenticated remote attacker could use this flaw to retrieve the content of certain files and trigger a denial of service, or in certain circumstances, execute arbitrary code on the Spacewalk server.

CVSS3: 8.6
fstec
почти 6 лет назад

Уязвимость компонента /rpc/api программного средства для управления системами Red Hat Spacewalk, позволяющая нарушителю раскрыть защищаемую информацию и вызвать отказ в обслуживании или выполнить произвольный код

EPSS

Процентиль: 91%
0.07131
Низкий

8.6 High

CVSS3

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-611
CWE-611