9.1
CVE-2023-36649
- EPSS 0.1%
- Veröffentlicht 12.12.2023 01:15:10
- Zuletzt bearbeitet 21.11.2024 08:10:12
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Insertion of sensitive information in the centralized (Grafana) logging system in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate other users in web management and the REST API by reading JWT tokens from logs (as a Granafa authenticated user) or from the Loki REST API without authentication.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Prolion ≫ Cryptospike Version3.0.15 Updatep2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.1% | 0.29 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
CWE-532 Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.