8.8
CVE-2022-0721
- EPSS 1.38%
- Veröffentlicht 23.02.2022 11:15:08
- Zuletzt bearbeitet 21.11.2024 06:39:15
- Quelle security@huntr.dev
- CVE-Watchlists
- Unerledigt
Insertion of Sensitive Information Into Debugging Code in microweber/microweber
Insertion of Sensitive Information Into Debugging Code in GitHub repository microweber/microweber prior to 1.3.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microweber ≫ Microweber Version < 1.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.38% | 0.685 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
| security@huntr.dev | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-215 Insertion of Sensitive Information Into Debugging Code
The product inserts sensitive information into debugging code, which could expose this information if the debugging code is not disabled in production.
https://github.com/microweber/microweber/commit/b12e1a490c79460bff019f34b2e17112249b16ec
https://huntr.dev/bounties/ae267d39-9750-4c69-be8b-4f915da089fb