Описание
Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. A remote, unauthenticated attacker could send requests to configuration files and obtain leaked secrets. Fixed in 8.1.0 alpha.
Ссылки
- Patch
- Third Party Advisory
- Broken Link
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:csprousers:csweb:8.0.1:*:*:*:*:*:*:*
EPSS
Процентиль: 13%
0.00043
Низкий
9.1 Critical
CVSS3
7.5 High
CVSS3
Дефекты
CWE-200
Связанные уязвимости
CVSS3: 9.1
github
14 дней назад
Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. A remote, unauthenticated attacker could send requests to configuration files and obtain leaked secrets. Fixed in 8.1.0 alpha.
EPSS
Процентиль: 13%
0.00043
Низкий
9.1 Critical
CVSS3
7.5 High
CVSS3
Дефекты
CWE-200