Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-25958

Опубликовано: 30 авг. 2021
Источник: nvd
CVSS3: 6.5
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

In Apache Ofbiz, versions v17.12.01 to v17.12.07 implement a try catch exception to handle errors at multiple locations but leaks out sensitive table info which may aid the attacker for further recon. A user can register with a very long password, but when he tries to login with it an exception occurs.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:*
Версия от 17.12.01 (включая) до 17.12.08 (исключая)

EPSS

Процентиль: 83%
0.02028
Низкий

6.5 Medium

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-209
CWE-209

Связанные уязвимости

github
больше 3 лет назад

In Apache Ofbiz, versions v17.12.01 to v17.12.07 implement a try catch exception to handle errors at multiple locations but leaks out sensitive table info which may aid the attacker for further recon. A user can register with a very long password, but when he tries to login with it an exception occurs.

EPSS

Процентиль: 83%
0.02028
Низкий

6.5 Medium

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-209
CWE-209