Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-42015

Опубликовано: 09 нояб. 2021
Источник: nvd
CVSS3: 5.5
CVSS2: 1.9
EPSS Низкий

Описание

A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.26), Mendix Applications using Mendix 8 (All versions < V8.18.12), Mendix Applications using Mendix 9 (All versions < V9.6.1). Applications built with affected versions of Mendix Studio Pro do not prevent file documents from being cached when files are opened or downloaded using a browser. This could allow a local attacker to read those documents by exploring the browser cache.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:mendix:mendix:*:*:*:*:*:*:*:*
Версия до 7.23.26 (исключая)
cpe:2.3:a:mendix:mendix:*:*:*:*:*:*:*:*
Версия от 8.0.0 (включая) до 8.18.12 (исключая)
cpe:2.3:a:mendix:mendix:*:*:*:*:*:*:*:*
Версия от 9.0.0 (включая) до 9.6.1 (исключая)

EPSS

Процентиль: 32%
0.00125
Низкий

5.5 Medium

CVSS3

1.9 Low

CVSS2

Дефекты

CWE-525

Связанные уязвимости

github
больше 3 лет назад

A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.26), Mendix Applications using Mendix 8 (All versions < V8.18.12), Mendix Applications using Mendix 9 (All versions < V9.6.1). Applications built with affected versions of Mendix Studio Pro do not prevent file documents from being cached when files are opened or downloaded using a browser. This could allow a local attacker to read those documents by exploring the browser cache.

EPSS

Процентиль: 32%
0.00125
Низкий

5.5 Medium

CVSS3

1.9 Low

CVSS2

Дефекты

CWE-525