PT-2023-30488 · Themeisle · Themeisle Cloud Templates & Patterns Collection
Joshua Chan
·
Publicado
2023-11-14
·
Atualizado
2023-11-30
·
CVE-2023-47529
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ThemeIsle Cloud Templates & Patterns collection versions 1.2.2 and earlier
Description
The issue is related to the exposure of sensitive information to an unauthorized actor. This is due to a sensitive information exposure via log file.
Recommendations
For ThemeIsle Cloud Templates & Patterns collection versions 1.2.2 and earlier, update to a version later than 1.2.2 to resolve the issue.
As a temporary workaround, consider restricting access to log files to minimize the risk of exploitation.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Themeisle Cloud Templates & Patterns Collection