Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-0833

Опубликовано: 14 фев. 2023
Источник: redhat
CVSS3: 4.7

Описание

A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information disclosure flaw via an exception triggered by a header containing an illegal value. This issue could allow an authenticated attacker to access information outside of their regular permissions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
streams for Apache KafkaokhttpAffected
Red Hat AMQ Streams 2.2.1FixedRHSA-2023:124114.03.2023
Red Hat AMQ Streams 2.4.0FixedRHSA-2023:322318.05.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-209
https://bugzilla.redhat.com/show_bug.cgi?id=2169845Streams: component version with information disclosure flaw

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
nvd
больше 2 лет назад

A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information disclosure flaw via an exception triggered by a header containing an illegal value. This issue could allow an authenticated attacker to access information outside of their regular permissions.

CVSS3: 4.7
github
больше 2 лет назад

A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information disclosure flaw via an exception triggered by a header containing an illegal value. This issue could allow an authenticated attacker to access information outside of their regular permissions.

4.7 Medium

CVSS3