Логотип exploitDog
bind:CVE-2026-30928
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-30928

Количество 4

Количество 4

ubuntu логотип

CVE-2026-30928

20 дней назад

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, the /api/4/config REST API endpoint returns the entire parsed Glances configuration file (glances.conf) via self.config.as_dict() with no filtering of sensitive values. The configuration file contains credentials for all configured backend services including database passwords, API tokens, JWT signing keys, and SSL key passwords. This vulnerability is fixed in 4.5.1.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-30928

20 дней назад

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, the /api/4/config REST API endpoint returns the entire parsed Glances configuration file (glances.conf) via self.config.as_dict() with no filtering of sensitive values. The configuration file contains credentials for all configured backend services including database passwords, API tokens, JWT signing keys, and SSL key passwords. This vulnerability is fixed in 4.5.1.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-30928

20 дней назад

Glances is an open-source system cross-platform monitoring tool. Prior ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-gh4x-f7cq-wwx6

20 дней назад

Glances Exposes Unauthenticated Configuration Secrets

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-30928

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, the /api/4/config REST API endpoint returns the entire parsed Glances configuration file (glances.conf) via self.config.as_dict() with no filtering of sensitive values. The configuration file contains credentials for all configured backend services including database passwords, API tokens, JWT signing keys, and SSL key passwords. This vulnerability is fixed in 4.5.1.

CVSS3: 7.5
3%
Низкий
20 дней назад
nvd логотип
CVE-2026-30928

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, the /api/4/config REST API endpoint returns the entire parsed Glances configuration file (glances.conf) via self.config.as_dict() with no filtering of sensitive values. The configuration file contains credentials for all configured backend services including database passwords, API tokens, JWT signing keys, and SSL key passwords. This vulnerability is fixed in 4.5.1.

CVSS3: 7.5
3%
Низкий
20 дней назад
debian логотип
CVE-2026-30928

Glances is an open-source system cross-platform monitoring tool. Prior ...

CVSS3: 7.5
3%
Низкий
20 дней назад
github логотип
GHSA-gh4x-f7cq-wwx6

Glances Exposes Unauthenticated Configuration Secrets

3%
Низкий
20 дней назад

Уязвимостей на страницу