Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-14955

Опубликовано: 25 сент. 2017
Источник: redhat
CVSS3: 6.5
EPSS Средний

Описание

Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user information by reading a GUI crash report.

Отчет

Red Hat Gluster Storage 3 is not affected because affected code is not shipped in the product. Affected code is present in check-mk-multisite rpm which is not shipped in this product.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Storage 3check-mkNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-362
https://bugzilla.redhat.com/show_bug.cgi?id=1497971check-mk: Mishandles certain errors within the failed-login save feature because of a race condition

EPSS

Процентиль: 95%
0.19623
Средний

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 8 лет назад

Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user information by reading a GUI crash report.

CVSS3: 5.9
nvd
больше 8 лет назад

Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user information by reading a GUI crash report.

CVSS3: 5.9
debian
больше 8 лет назад

Check_MK before 1.2.8p26 mishandles certain errors within the failed-l ...

CVSS3: 5.9
github
больше 3 лет назад

Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user information by reading a GUI crash report.

EPSS

Процентиль: 95%
0.19623
Средний

6.5 Medium

CVSS3