Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33302
HistoryDec 14, 2021 - 4:34 a.m.

Side-Channel Attack

2021-12-1404:34:02
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4

0.001 Low

EPSS

Percentile

27.0%

github.com/sourcegraph/sourcegraph is vulnerable to side channel attack. The attack is possible because the library does not properly exclude the private source code search results in ‘search_results.go’ , allowing an authenticated attacker to check specific string and API keys exists in private source code by using saved searches or code monitors.

0.001 Low

EPSS

Percentile

27.0%

Related for VERACODE:33302