Описание
A class name enumeration was found in Keyfactor SignServer versions prior to 7.3.2. Setting any chosen class name to any of the properties requiring a class path and the provided class is not expected to return different errors if the class exists in deployment or not. This returns information about the classes loaded in the application or not to the clientside.
Уязвимые конфигурации
Конфигурация 1Версия до 7.3.1 (исключая)
cpe:2.3:a:keyfactor:signserver:*:*:*:*:*:*:*:*
EPSS
Процентиль: 17%
0.00054
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-284
Связанные уязвимости
CVSS3: 6.5
github
3 месяца назад
Keyfactor SignServer before 7.3.1 has Incorrect Access Control, issue 3 of 3.
EPSS
Процентиль: 17%
0.00054
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-284