Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:46202
HistoryApr 04, 2024 - 6:31 a.m.

Information Disclosure

2024-04-0406:31:48
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5
yaql vulnerability
improper handling
attribute access
format function
unauthorized users
sensitive information
service account credentials

6.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.8%

yaql is vulnerable to Information Disclosure. The vulnerability is due to improper handling of attribute access in the YAQL library’s ‘format’ function, allowing unauthorized users to access sensitive information, including service account credentials.

CPENameOperatorVersion
yaqlle2.0.1
yaqlle2.0.1

6.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.8%