Описание
An observable response discrepancy in the Gallagher Command Centre RESTAPI allows an insufficiently-privileged user to infer the presence of items that would not otherwise be viewable.
This issue affects: Gallagher Command Centre 8.70 prior to vEL8.70.1787 (MR2), 8.60 prior to vEL8.60.2039 (MR4), all version of 8.50 and prior.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 8.50 (включая)Версия от 8.60 (включая) до 8.60.2039 (исключая)Версия от 8.70 (включая) до 8.70.1787 (исключая)
Одно из
cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*
cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*
cpe:2.3:a:gallagher:command_centre:*:*:*:*:*:*:*:*
EPSS
Процентиль: 38%
0.00168
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-204
CWE-203
Связанные уязвимости
CVSS3: 4.3
github
около 2 лет назад
An observable response discrepancy in the Gallagher Command Centre RESTAPI allows an insufficiently-privileged user to infer the presence of items that would not otherwise be viewable. This issue affects: Gallagher Command Centre 8.70 prior to vEL8.70.1787 (MR2), 8.60 prior to vEL8.60.2039 (MR4), all version of 8.50 and prior.
EPSS
Процентиль: 38%
0.00168
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-204
CWE-203