5.3
CVE-2020-11883
- EPSS 2.73%
- Veröffentlicht 17.04.2020 19:15:14
- Zuletzt bearbeitet 21.11.2024 04:58:49
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
In Divante vue-storefront-api through 1.11.1 and storefront-api through 1.0-rc.1, as used in VueStorefront PWA, unexpected HTTP requests lead to an exception that discloses the error stack trace, with absolute file paths and Node.js module names.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Divante ≫ Storefront-api Version1.0 Updaterc1
Divante ≫ Vue-storefront-api Version <= 1.11.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.73% | 0.855 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-209 Generation of Error Message Containing Sensitive Information
The product generates an error message that includes sensitive information about its environment, users, or associated data.