PT-2019-13942 · Pydio · Pydio

Publicado

2019-09-19

·

Atualizado

2019-09-19

·

CVE-2019-15032

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Pydio version 6.0.8
Description The issue concerns error reporting in Pydio when a directory allows unauthenticated uploads and the remote-upload option is used with the http://localhost:22 URL. This can lead to the disclosure of sensitive information, including the name of the user who created the directory and other internal server details.
Recommendations For Pydio version 6.0.8, consider restricting access to the remote-upload option or disabling unauthenticated uploads in directories to minimize the risk of information disclosure. Additionally, review server configurations to ensure that sensitive information is not exposed through error reporting.

Exploit

Correção

Generation of Error Message Containing Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-15032

Produtos afetados

Pydio