4.3

CVE-2022-3301

Exploit

Improper Cleanup on Thrown Exception in ikus060/rdiffweb

Improper Cleanup on Thrown Exception in GitHub repository ikus060/rdiffweb prior to 2.4.8.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ikus-softRdiffweb Version < 2.4.8
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.54% 0.409
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 2.4 0.9 1.4
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
security@huntr.dev 4.3 2.8 1.4
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CWE-460 Improper Cleanup on Thrown Exception

The product does not clean up its state or incorrectly cleans up its state when an exception is thrown, leading to unexpected state or control flow.

https://github.com/ikus060/rdiffweb/commit/5ac38b2a75becbab9f948bd5e37ecbcd9f0b362e
Patch
Third Party Advisory
https://huntr.dev/bounties/d3bf1e5d-055a-44b8-8d60-54ab966ed63a
Patch
Third Party Advisory
Exploit