PT-2018-17567 · Nibbleblog · Nibbleblog
Published
2018-02-01
·
Updated
2021-09-08
·
CVE-2018-6470
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Nibbleblog version 4.0.5
Description
The issue causes DS Store information to leak due to .DS Store files being present in each directory by default on macOS.
Recommendations
For Nibbleblog version 4.0.5, consider removing or restricting access to .DS Store files to minimize the risk of information leakage.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nibbleblog