Описание
Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, Hoverfly’s admin WebSocket endpoint /api/v2/ws/logs is not protected by the same authentication middleware that guards the REST admin API. Consequently, an unauthenticated remote attacker can stream real-time application logs (information disclosure) and/or gain insight into internal file paths, request/response bodies, and other potentially sensitive data emitted in logs. Version 1.12.0 contains a fix for the issue.
Уязвимые конфигурации
Конфигурация 1Версия до 1.12.0 (исключая)
cpe:2.3:a:hoverfly:hoverfly:*:*:*:*:*:*:*:*
EPSS
Процентиль: 36%
0.00149
Низкий
7.5 High
CVSS3
Дефекты
CWE-200
CWE-532
Связанные уязвимости
github
5 месяцев назад
WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled
EPSS
Процентиль: 36%
0.00149
Низкий
7.5 High
CVSS3
Дефекты
CWE-200
CWE-532