Lucene search

K
cve@huntrdevCVE-2023-4560
HistoryAug 28, 2023 - 1:15 a.m.

CVE-2023-4560

2023-08-2801:15:10
CWE-612
@huntrdev
web.nvd.nist.gov
87
cve-2023-4560
improper authorization
index containing sensitive information
github
repository
nvd

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

30.3%

Improper Authorization of Index Containing Sensitive Information in GitHub repository omeka/omeka-s prior to 4.0.4.

Affected configurations

Nvd
Node
omekaomeka_sRange<4.0.4
VendorProductVersionCPE
omekaomeka_s*cpe:2.3:a:omeka:omeka_s:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "omeka",
    "product": "omeka/omeka-s",
    "versions": [
      {
        "version": "unspecified",
        "lessThan": "4.0.4",
        "status": "affected",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

30.3%

Related for CVE-2023-4560