7.5

CVE-2017-6910

The HTTP and WebSocket engine components in the server in Kaazing Gateway before 4.5.3 hotfix-1, Gateway - JMS Edition before 4.0.5 hotfix-15, 4.0.6 before hotfix-4, 4.0.7, 4.0.9 before hotfix-19, 4.4.x before 4.4.2 hotfix-1, 4.5.x before 4.5.3 hotfix-1, and Gateway Community and Enterprise Editions before 5.6.0 allow remote attackers to bypass intended access restrictions and obtain sensitive information via vectors related to HTTP request handling.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Kaazing ≫ Kaazing Gateway Version < 4.5.3
Kaazing ≫ Kaazing Gateway Version 4.5.3
Kaazing ≫ Kaazing Gateway Version 4.5.3 Update hotfix1
Kaazing ≫ Kaazing Gateway Update hotfix1 SwEdition jms Version >= 4.4.0 < 4.4.2
Kaazing ≫ Kaazing Gateway SwEdition jms Version >= 4.5.0 < 4.5.3
Kaazing ≫ Kaazing Gateway Version 4.0.5 SwEdition jms
Kaazing ≫ Kaazing Gateway Version 4.0.6 SwEdition jms
Kaazing ≫ Kaazing Gateway Version 4.0.6 Update hotfix2 SwEdition jms
Kaazing ≫ Kaazing Gateway Version 4.0.7 SwEdition jms
Kaazing ≫ Kaazing Gateway Version 4.4.2 Update hotfix1 SwEdition jms
Kaazing ≫ Kaazing Gateway Version 4.5.3 Update hotfix1 SwEdition jms
Tenefit ≫ Kaazing Websocket Gateway SwEdition community Version < 5.6.0
Tenefit ≫ Kaazing Websocket Gateway SwEdition enterprise Version < 5.6.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.97% 0.778
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

https://support.kaazing.com/hc/en-us/articles/115004752368
Vendor Advisory
Mitigation