Описание
In Jeedom through 4.1.19, a bug allows a remote attacker to bypass API access and retrieve users credentials.
Ссылки
- Release NotesThird Party Advisory
- https://www.synacktiv.com/sites/default/files/2021-10/advisory_Jeedom_Auth_Bypass_CVE-2021-42557.pdfExploitThird Party Advisory
- Release NotesThird Party Advisory
- https://www.synacktiv.com/sites/default/files/2021-10/advisory_Jeedom_Auth_Bypass_CVE-2021-42557.pdfExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.1.19 (включая)
cpe:2.3:a:jeedom:jeedom:*:*:*:*:*:*:*:*
EPSS
Процентиль: 66%
0.00507
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
In Jeedom through 4.1.19, a bug allows a remote attacker to bypass API access and retrieve users credentials.
EPSS
Процентиль: 66%
0.00507
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
NVD-CWE-Other