Логотип exploitDog
bind:CVE-2022-21704
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-21704

Количество 5

Количество 5

ubuntu логотип

CVE-2022-21704

около 4 лет назад

log4js-node is a port of log4js to node.js. In affected versions default file permissions for log files created by the file, fileSync and dateFile appenders are world-readable (in unix). This could cause problems if log files contain sensitive information. This would affect any users that have not supplied their own permissions for the files via the mode parameter in the config. Users are advised to update.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2022-21704

около 4 лет назад

log4js-node is a port of log4js to node.js. In affected versions default file permissions for log files created by the file, fileSync and dateFile appenders are world-readable (in unix). This could cause problems if log files contain sensitive information. This would affect any users that have not supplied their own permissions for the files via the mode parameter in the config. Users are advised to update.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2022-21704

около 4 лет назад

log4js-node is a port of log4js to node.js. In affected versions defau ...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-82v2-mx6x-wq7q

около 4 лет назад

Incorrect Default Permissions in log4js

CVSS3: 5.5
EPSS: Низкий
fstec логотип

BDU:2022-01070

около 4 лет назад

Уязвимость библиотеки журналирования log4js-node, связанная с недостатками разграничения доступа к директории, позволяющая нарушителю получить доступ к конфиденциальной информации

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-21704

log4js-node is a port of log4js to node.js. In affected versions default file permissions for log files created by the file, fileSync and dateFile appenders are world-readable (in unix). This could cause problems if log files contain sensitive information. This would affect any users that have not supplied their own permissions for the files via the mode parameter in the config. Users are advised to update.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-21704

log4js-node is a port of log4js to node.js. In affected versions default file permissions for log files created by the file, fileSync and dateFile appenders are world-readable (in unix). This could cause problems if log files contain sensitive information. This would affect any users that have not supplied their own permissions for the files via the mode parameter in the config. Users are advised to update.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
debian логотип
CVE-2022-21704

log4js-node is a port of log4js to node.js. In affected versions defau ...

CVSS3: 5.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-82v2-mx6x-wq7q

Incorrect Default Permissions in log4js

CVSS3: 5.5
0%
Низкий
около 4 лет назад
fstec логотип
BDU:2022-01070

Уязвимость библиотеки журналирования log4js-node, связанная с недостатками разграничения доступа к директории, позволяющая нарушителю получить доступ к конфиденциальной информации

CVSS3: 5.5
0%
Низкий
около 4 лет назад

Уязвимостей на страницу