Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-34968

Опубликовано: 19 июл. 2023
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious client or an attacker with a targeted RPC request to view the information that is part of the disclosed path.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6sambaOut of support scope
Red Hat Enterprise Linux 6samba4Out of support scope
Red Hat Enterprise Linux 7sambaOut of support scope
Red Hat Storage 3sambaAffected
Red Hat Enterprise Linux 8sambaFixedRHSA-2023:713914.11.2023
Red Hat Enterprise Linux 8sambaFixedRHSA-2023:713914.11.2023
Red Hat Enterprise Linux 8.6 Extended Update SupportsambaFixedRHSA-2024:042325.01.2024
Red Hat Enterprise Linux 8.8 Extended Update SupportsambaFixedRHSA-2024:058030.01.2024
Red Hat Enterprise Linux 9sambaFixedRHSA-2023:666707.11.2023
Red Hat Enterprise Linux 9sambaFixedRHSA-2023:666707.11.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-201
https://bugzilla.redhat.com/show_bug.cgi?id=2222795samba: spotlight server-side share path disclosure

EPSS

Процентиль: 82%
0.01859
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 2 лет назад

A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious client or an attacker with a targeted RPC request to view the information that is part of the disclosed path.

CVSS3: 5.3
nvd
около 2 лет назад

A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious client or an attacker with a targeted RPC request to view the information that is part of the disclosed path.

CVSS3: 5.3
debian
около 2 лет назад

A path disclosure vulnerability was found in Samba. As part of the Spo ...

CVSS3: 5.3
github
около 2 лет назад

A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious client or an attacker with a targeted RPC request to view the information that is part of the disclosed path.

CVSS3: 5.3
fstec
около 2 лет назад

Уязвимость пакета программ сетевого взаимодействия Samba, связанная с раскрытием информации, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 82%
0.01859
Низкий

5.3 Medium

CVSS3