Логотип exploitDog
bind:CVE-2023-1783
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-1783

Количество 2

Количество 2

nvd логотип

CVE-2023-1783

больше 2 лет назад

OrangeScrum version 2.0.11 allows an external attacker to remotely obtain AWS instance credentials. This is possible because the application does not properly validate the HTML content to be converted to PDF.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-g9fp-4f3g-gqmr

больше 2 лет назад

OrangeScrum version 2.0.11 allows an external attacker to remotely obtain AWS instance credentials. This is possible because the application does not properly validate the HTML content to be converted to PDF.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-1783

OrangeScrum version 2.0.11 allows an external attacker to remotely obtain AWS instance credentials. This is possible because the application does not properly validate the HTML content to be converted to PDF.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-g9fp-4f3g-gqmr

OrangeScrum version 2.0.11 allows an external attacker to remotely obtain AWS instance credentials. This is possible because the application does not properly validate the HTML content to be converted to PDF.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу