Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-46237

Опубликовано: 31 окт. 2023
Источник: nvd
CVSS3: 5.8
CVSS3: 5.3
EPSS Низкий

Описание

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10, an endpoint intended to offer limited enumeration abilities to authenticated users was accessible to unauthenticated users. This enabled unauthenticated users to discover files and their respective paths that were visible to the Apache user group. Version 1.5.10 contains a patch for this issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:fogproject:fogproject:*:*:*:*:*:*:*:*
Версия до 1.5.10 (исключая)

EPSS

Процентиль: 62%
0.00422
Низкий

5.8 Medium

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-22

EPSS

Процентиль: 62%
0.00422
Низкий

5.8 Medium

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-22