Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2026-33533

5 месяцев назад

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, the Glances XML-RPC server (activated with glances -s or glances --server) sends Access-Control-Allow-Origin: * on every HTTP response. Because the XML-RPC handler does not validate the Content-Type header, an attacker-controlled webpage can issue a CORS "simple request" (POST with Content-Type: text/plain) containing a valid XML-RPC payload. The browser sends the request without a preflight check, the server processes the XML body and returns the full system monitoring dataset, and the wildcard CORS header lets the attacker's JavaScript read the response. The result is complete exfiltration of hostname, OS version, IP addresses, CPU/memory/disk/network stats, and the full process list including command lines (which often contain tokens, passwords, or internal paths). This issue has been patched in version 4.5.3.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-33533

5 месяцев назад

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, the Glances XML-RPC server (activated with glances -s or glances --server) sends Access-Control-Allow-Origin: * on every HTTP response. Because the XML-RPC handler does not validate the Content-Type header, an attacker-controlled webpage can issue a CORS "simple request" (POST with Content-Type: text/plain) containing a valid XML-RPC payload. The browser sends the request without a preflight check, the server processes the XML body and returns the full system monitoring dataset, and the wildcard CORS header lets the attacker's JavaScript read the response. The result is complete exfiltration of hostname, OS version, IP addresses, CPU/memory/disk/network stats, and the full process list including command lines (which often contain tokens, passwords, or internal paths). This issue has been patched in version 4.5.3.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2026-33533

5 месяцев назад

Glances is an open-source system cross-platform monitoring tool. Prior ...

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20260709-80-0042

около 1 месяца назад

Уязвимость glances

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-7p93-6934-f4q7

5 месяцев назад

Glances Vulnerable to Cross-Origin System Information Disclosure via XML-RPC Server CORS Wildcard

EPSS: Низкий
fstec логотип

BDU:2026-11019

5 месяцев назад

Уязвимость сервера XML-RPC инструмента мониторинга Glances, позволяющая нарушителю оказать воздействие на конфиденциальность защищаемой информации

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-33533

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, the Glances XML-RPC server (activated with glances -s or glances --server) sends Access-Control-Allow-Origin: * on every HTTP response. Because the XML-RPC handler does not validate the Content-Type header, an attacker-controlled webpage can issue a CORS "simple request" (POST with Content-Type: text/plain) containing a valid XML-RPC payload. The browser sends the request without a preflight check, the server processes the XML body and returns the full system monitoring dataset, and the wildcard CORS header lets the attacker's JavaScript read the response. The result is complete exfiltration of hostname, OS version, IP addresses, CPU/memory/disk/network stats, and the full process list including command lines (which often contain tokens, passwords, or internal paths). This issue has been patched in version 4.5.3.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-33533

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, the Glances XML-RPC server (activated with glances -s or glances --server) sends Access-Control-Allow-Origin: * on every HTTP response. Because the XML-RPC handler does not validate the Content-Type header, an attacker-controlled webpage can issue a CORS "simple request" (POST with Content-Type: text/plain) containing a valid XML-RPC payload. The browser sends the request without a preflight check, the server processes the XML body and returns the full system monitoring dataset, and the wildcard CORS header lets the attacker's JavaScript read the response. The result is complete exfiltration of hostname, OS version, IP addresses, CPU/memory/disk/network stats, and the full process list including command lines (which often contain tokens, passwords, or internal paths). This issue has been patched in version 4.5.3.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
debian логотип
CVE-2026-33533

Glances is an open-source system cross-platform monitoring tool. Prior ...

CVSS3: 6.5
0%
Низкий
5 месяцев назад
redos логотип
ROS-20260709-80-0042

Уязвимость glances

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-7p93-6934-f4q7

Glances Vulnerable to Cross-Origin System Information Disclosure via XML-RPC Server CORS Wildcard

0%
Низкий
5 месяцев назад
fstec логотип
BDU:2026-11019

Уязвимость сервера XML-RPC инструмента мониторинга Glances, позволяющая нарушителю оказать воздействие на конфиденциальность защищаемой информации

CVSS3: 6.5
0%
Низкий
5 месяцев назад

Уязвимостей на страницу