Логотип exploitDog
bind:CVE-2023-36649
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-36649

Количество 2

Количество 2

nvd логотип

CVE-2023-36649

около 2 лет назад

Insertion of sensitive information in the centralized (Grafana) logging system in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate other users in web management and the REST API by reading JWT tokens from logs (as a Granafa authenticated user) or from the Loki REST API without authentication.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-qg95-6496-m556

около 2 лет назад

Insertion of sensitive information in the centralized (Grafana) logging system in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate other users in web management and the REST API by reading JWT tokens from logs (as a Granafa authenticated user) or from the Loki REST API without authentication.

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-36649

Insertion of sensitive information in the centralized (Grafana) logging system in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate other users in web management and the REST API by reading JWT tokens from logs (as a Granafa authenticated user) or from the Loki REST API without authentication.

CVSS3: 9.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-qg95-6496-m556

Insertion of sensitive information in the centralized (Grafana) logging system in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate other users in web management and the REST API by reading JWT tokens from logs (as a Granafa authenticated user) or from the Loki REST API without authentication.

CVSS3: 9.1
0%
Низкий
около 2 лет назад

Уязвимостей на страницу