Логотип exploitDog
bind:CVE-2021-39174
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-39174

Количество 3

Количество 3

nvd логотип

CVE-2021-39174

больше 4 лет назад

Cachet is an open source status page system. Prior to version 2.5.1, authenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret (`APP_KEY`) and various passwords (email, database, etc). This issue was addressed in version 2.5.1 by improving `UpdateConfigCommandHandler` and preventing the use of nested variables in the resulting dotenv configuration file. As a workaround, only allow trusted source IP addresses to access to the administration dashboard.

CVSS3: 8.8
EPSS: Средний
debian логотип

CVE-2021-39174

больше 4 лет назад

Cachet is an open source status page system. Prior to version 2.5.1, a ...

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-88f9-7xxh-c688

больше 4 лет назад

Cachet configuration leak

CVSS3: 8.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-39174

Cachet is an open source status page system. Prior to version 2.5.1, authenticated users, regardless of their privileges (User or Admin), can leak the value of any configuration entry of the dotenv file, e.g. the application secret (`APP_KEY`) and various passwords (email, database, etc). This issue was addressed in version 2.5.1 by improving `UpdateConfigCommandHandler` and preventing the use of nested variables in the resulting dotenv configuration file. As a workaround, only allow trusted source IP addresses to access to the administration dashboard.

CVSS3: 8.8
49%
Средний
больше 4 лет назад
debian логотип
CVE-2021-39174

Cachet is an open source status page system. Prior to version 2.5.1, a ...

CVSS3: 8.8
49%
Средний
больше 4 лет назад
github логотип
GHSA-88f9-7xxh-c688

Cachet configuration leak

CVSS3: 8.8
49%
Средний
больше 4 лет назад

Уязвимостей на страницу