PT-2022-27674 · Unknown · Planet Estream

Hrvoje Filakovic

+2

·

Published

2022-12-25

·

Updated

2023-01-04

·

CVE-2022-45895

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Planet eStream versions prior to 6.72.10.07
Description The issue discloses sensitive information related to the ON cookie, which can be found in the HTML source code for "Default.aspx" in certain situations, and the "WhoAmI" endpoint, which can lead to path disclosure.
Recommendations For versions prior to 6.72.10.07, update to version 6.72.10.07 or later to resolve the issue. As a temporary workaround, consider restricting access to the "WhoAmI" endpoint and limiting the exposure of the ON cookie in the HTML source code for "Default.aspx" until a patch is applied.

Exploit

Fix

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

CVE-2022-45895

Affected Products

Planet Estream