Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:44989
HistoryJan 09, 2024 - 7:57 a.m.

Log Injection

2024-01-0907:57:07
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5
pyload-ng
log injection
api_blueprint.py
app_blueprint.py
validation
error logging
vulnerability
log files
exploitation

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

6.7 Medium

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

76.8%

pyload-ng is vulnerable to Log Injection. The vulnerability is caused due to a lack of validation while logging an error in api_blueprint.py and app_blueprint.py. An attacker can corrupt log files exploiting this vulnerability.

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

6.7 Medium

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

76.8%