5.3

CVE-2025-70040

An issue pertaining to CWE-532: Insertion of Sensitive Information into Log File was discovered in LupinLin1 jimeng-web-mcp v2.1.2. This allows an attacker to obtain sensitive information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lupinlin1Jimeng Web Mcp Server Version2.1.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.24% 0.15
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.

https://gist.github.com/zcxlighthouse/73b4ea07d1056ca9f100d11bfb4c8aa5
Third Party Advisory
https://github.com/LupinLin1
Product
https://github.com/LupinLin1/jimeng-web-mcp
Product