Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-1098

Опубликовано: 31 янв. 2024
Источник: nvd
CVSS3: 4.3
CVSS3: 7.5
CVSS2: 3.3
EPSS Низкий

Описание

A vulnerability was found in Rebuild up to 3.5.5 and classified as problematic. This issue affects the function QiniuCloud.getStorageFile of the file /filex/proxy-download. The manipulation of the argument url leads to information disclosure. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252455.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ruifang-tech:rebuild:*:*:*:*:*:*:*:*
Версия до 3.5.5 (включая)

EPSS

Процентиль: 33%
0.00133
Низкий

4.3 Medium

CVSS3

7.5 High

CVSS3

3.3 Low

CVSS2

Дефекты

CWE-200
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 4.3
github
около 2 лет назад

A vulnerability was found in Rebuild up to 3.5.5 and classified as problematic. This issue affects the function QiniuCloud.getStorageFile of the file /filex/proxy-download. The manipulation of the argument url leads to information disclosure. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252455.

EPSS

Процентиль: 33%
0.00133
Низкий

4.3 Medium

CVSS3

7.5 High

CVSS3

3.3 Low

CVSS2

Дефекты

CWE-200
NVD-CWE-noinfo