Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-1663

Опубликовано: 29 мар. 2023
Источник: nvd
CVSS3: 6.5
CVSS3: 5.3
EPSS Низкий

Описание

Coverity versions prior to 2023.3.2 are vulnerable to forced browsing, which exposes authenticated resources to unauthorized actors. The root cause of this vulnerability is an insecurely configured servlet mapping for the underlying Apache Tomcat server. As a result, the downloads directory and its contents are accessible. 5.9 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L/E:P/RL:O/RC:C)

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:synopsys:coverity:*:*:*:*:*:*:*:*
Версия до 2023.3.2 (исключая)

EPSS

Процентиль: 32%
0.00123
Низкий

6.5 Medium

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-425
CWE-425

Связанные уязвимости

CVSS3: 5.3
github
почти 3 года назад

Coverity versions prior to 2023.3.2 are vulnerable to forced browsing, which exposes authenticated resources to unauthorized actors. The root cause of this vulnerability is an insecurely configured servlet mapping for the underlying Apache Tomcat server. As a result, the downloads directory and its contents are accessible. 5.9 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L/E:P/RL:O/RC:C)

EPSS

Процентиль: 32%
0.00123
Низкий

6.5 Medium

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-425
CWE-425