Логотип exploitDog
bind:CVE-2024-23329
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-23329

Количество 2

Количество 2

nvd логотип

CVE-2024-23329

около 2 лет назад

changedetection.io is an open source tool designed to monitor websites for content changes. In affected versions the API endpoint `/api/v1/watch/<uuid>/history` can be accessed by any unauthorized user. As a result any unauthorized user can check one's watch history. However, because unauthorized party first needs to know a watch UUID, and the watch history endpoint itself returns only paths to the snapshot on the server, an impact on users' data privacy is minimal. This issue has been addressed in version 0.45.13. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-hcvp-2cc7-jrwr

около 2 лет назад

changedetection.io API endpoint is not secured with API token

CVSS3: 3.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-23329

changedetection.io is an open source tool designed to monitor websites for content changes. In affected versions the API endpoint `/api/v1/watch/<uuid>/history` can be accessed by any unauthorized user. As a result any unauthorized user can check one's watch history. However, because unauthorized party first needs to know a watch UUID, and the watch history endpoint itself returns only paths to the snapshot on the server, an impact on users' data privacy is minimal. This issue has been addressed in version 0.45.13. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 3.7
0%
Низкий
около 2 лет назад
github логотип
GHSA-hcvp-2cc7-jrwr

changedetection.io API endpoint is not secured with API token

CVSS3: 3.7
0%
Низкий
около 2 лет назад

Уязвимостей на страницу