PT-2024-29886 · Unknown · Fog Server

Abotzung

·

Published

2024-08-02

·

Updated

2024-09-10

·

CVE-2024-42349

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions FOG Server versions 1.5.10.41.4 and earlier
Description The issue concerns the exposure of sensitive information via logs stored on the web server. Specifically, FOG Server creates two logs, fog login accepted.log and fog login failed.log, on the root of the web server, which can leak authorized and rejected logins. These logs contain the name of the user account used to manage FOG, the IP address of the computer used to login, and the User-Agent.
Recommendations For FOG Server versions 1.5.10.41.4 and earlier, update to version 1.5.10.47 or later to fix the issue. As a temporary workaround, consider restricting access to the fog login accepted.log and fog login failed.log files to minimize the risk of exploitation.

Exploit

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2024-42349
GHSA-697M-3C4P-G29H

Affected Products

Fog Server