Lucene search

K
osvGoogleOSV:GHSA-JR83-VR4J-MP6P
HistoryMay 14, 2022 - 12:57 a.m.

web2py exposure of sensitive information

2022-05-1400:57:47
Google
osv.dev
1

7.8 High

AI Score

Confidence

Low

0.021 Low

EPSS

Percentile

89.1%

web2py before 2.14.2 allows remote attackers to obtain the session_cookie_key value via a direct request to examples/simple_examples/status. NOTE: this issue can be leveraged by remote attackers to execute arbitrary code using CVE-2016-3957.

CPENameOperatorVersion
web2pyeq2.1.1
web2pyeq1.98.2
web2pyeq1.96.4

7.8 High

AI Score

Confidence

Low

0.021 Low

EPSS

Percentile

89.1%