PT-2023-29920 · Apache · Apache

0X41C

·

Publicado

2023-10-31

·

Atualizado

2023-11-08

·

CVE-2023-46237

CVSS v3.1

5.8

Média

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions FOG versions prior to 1.5.10
Description The issue affects FOG, a free open-source cloning/imaging/rescue suite/inventory management system. An endpoint intended for authenticated users to have limited enumeration abilities was accessible to unauthenticated users. This allowed unauthenticated users to discover files and their paths visible to the Apache user group.
Recommendations For versions prior to 1.5.10, update to version 1.5.10 to resolve the issue. As a temporary workaround, consider restricting access to the affected endpoint until the patch is applied.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-46237
GHSA-FFP9-RHFM-98C2

Produtos afetados

Apache