Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-4286
HistoryDec 27, 2022 - 12:00 a.m.

CVE-2021-4286

2022-12-2700:00:00
ubuntu.com
ubuntu.com
5
information exposure discrepancy
calculate_x function
version 1.0.17
dba52642f5e95d3da7af1780561213ee6053195f
vdb-216875
unix

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.001 Low

EPSS

Percentile

49.3%

A vulnerability, which was classified as problematic, has been found in
cocagne pysrp up to 1.0.16. This issue affects the function calculate_x of
the file srp/_ctsrp.py. The manipulation leads to information exposure
through discrepancy. Upgrading to version 1.0.17 is able to address this
issue. The name of the patch is dba52642f5e95d3da7af1780561213ee6053195f.
It is recommended to upgrade the affected component. The associated
identifier of this vulnerability is VDB-216875.

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.001 Low

EPSS

Percentile

49.3%

Related for UB:CVE-2021-4286