Описание
Landscape's server-status page exposed sensitive system information. This data leak included GET requests which contain information to attack and leak further information from the Landscape API.
Ссылки
- Issue TrackingMitigationVendor Advisory
- Issue TrackingMitigationVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 19.10.5 (исключая)
cpe:2.3:a:canonical:landscape:*:*:*:*:*:*:*:*
EPSS
Процентиль: 38%
0.00168
Низкий
9.3 Critical
CVSS3
8.2 High
CVSS3
Дефекты
CWE-497
CWE-668
Связанные уязвимости
CVSS3: 9.3
github
больше 2 лет назад
Landscape's server-status page exposed sensitive system information. This data leak included GET requests which contain information to attack and leak further information from the Landscape API.
EPSS
Процентиль: 38%
0.00168
Низкий
9.3 Critical
CVSS3
8.2 High
CVSS3
Дефекты
CWE-497
CWE-668