PT-2023-30488 · Themeisle · Themeisle Cloud Templates & Patterns Collection

Joshua Chan

·

Published

2023-11-14

·

Updated

2023-11-30

·

CVE-2023-47529

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ThemeIsle Cloud Templates & Patterns collection versions 1.2.2 and earlier
Description The issue is related to the exposure of sensitive information to an unauthorized actor. This is due to a sensitive information exposure via log file.
Recommendations For ThemeIsle Cloud Templates & Patterns collection versions 1.2.2 and earlier, update to a version later than 1.2.2 to resolve the issue. As a temporary workaround, consider restricting access to log files to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-47529

Affected Products

Themeisle Cloud Templates & Patterns Collection