Описание
Hard-coded credentials in mod-remote-storage versions under 1.7.2 and from 2.0.0 to 2.0.3 allows unauthorized users to gain read access to mod-inventory-storage records including instances, holdings, items, contributor-types, and identifier-types.
Ссылки
- Third Party Advisory
- Patch
- Vendor Advisory
- Third Party Advisory
- PatchVendor Advisory
- Third Party Advisory
- Patch
- Vendor Advisory
- Third Party Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.7.2 (исключая)Версия от 2.0.0 (включая) до 2.0.3 (исключая)
Одно из
cpe:2.3:a:openlibraryfoundation:mod-remote-storage:*:*:*:*:*:*:*:*
cpe:2.3:a:openlibraryfoundation:mod-remote-storage:*:*:*:*:*:*:*:*
EPSS
Процентиль: 59%
0.00389
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-798
CWE-798
Связанные уязвимости
CVSS3: 5.3
github
больше 2 лет назад
Hard-coded System User Credentials in Folio Data Export Spring module
EPSS
Процентиль: 59%
0.00389
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-798
CWE-798