Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-6496

Опубликовано: 16 сент. 2014
Источник: redhat
CVSS2: 5
EPSS Низкий

Описание

Red Hat Conga 0.12.2 allows remote attackers to obtain sensitive information via a crafted request to the (1) homebase, (2) cluster, (3) storage, (4) portal_skins/custom, or (5) logs Luci extension.

Multiple information leak flaws were found in the way conga processed luci site extension-related URL requests. A remote, unauthenticated attacker could issue a specially crafted HTTP request that, when processed, would result in unauthorized information disclosure.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5congaAffected
Red Hat Enterprise Linux 6luciNot affected
Red Hat Enterprise Linux 5congaFixedRHSA-2014:119416.09.2014

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-306->CWE-862->CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=971541conga: Multiple information leak flaws in various luci site extensions

EPSS

Процентиль: 48%
0.0025
Низкий

5 Medium

CVSS2

Связанные уязвимости

nvd
около 11 лет назад

Red Hat Conga 0.12.2 allows remote attackers to obtain sensitive information via a crafted request to the (1) homebase, (2) cluster, (3) storage, (4) portal_skins/custom, or (5) logs Luci extension.

github
больше 3 лет назад

Red Hat Conga 0.12.2 allows remote attackers to obtain sensitive information via a crafted request to the (1) homebase, (2) cluster, (3) storage, (4) portal_skins/custom, or (5) logs Luci extension.

oracle-oval
около 11 лет назад

ELSA-2014-1194: conga security and bug fix update (MODERATE)

EPSS

Процентиль: 48%
0.0025
Низкий

5 Medium

CVSS2