Lucene search

K
hackeroneKurohiroH1:1991428
HistoryMay 18, 2023 - 9:15 a.m.

Internet Bug Bounty: CVE-2023-28322: more POST-after-PUT confusion

2023-05-1809:15:01
kurohiro
hackerone.com
35
cwe-440 expected behavior violation
data injection
segfaults
sensitive information
bugbounty

0.001 Low

EPSS

Percentile

48.2%

Original Report:https://hackerone.com/reports/1954658

Impact

CWE-440: Expected Behavior Violation
An attacker could potentially inject data, either from stdin or from an unintended buffer. Further, without even an active attacker, this could lead to segfaults or sensitive information being exposed to an unintended recipient.