PT-2022-9018 · Pengu · Pengu

Published

2022-12-21

·

Updated

2022-12-28

·

CVE-2020-36623

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Pengu (affected versions not specified)
Description A vulnerability was found in Pengu, affecting the function runApp of the file src/index.js. This issue leads to cross-site request forgery and can be launched remotely.
Recommendations Apply a patch to fix this issue. The patch name is aea66f12b8cdfc3c8c50ad6a9c89d8307e9d0a91. As a temporary workaround, consider disabling the runApp function until a patch is available.

Fix

Incorrect Authorization

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-36623

Affected Products

Pengu