Publish GHSA-7fqm-jm52-f9vc

This commit is contained in:
advisory-database[bot]
2024-10-16 21:38:28 +00:00
parent ee3f8b7701
commit bc0fe9fad1
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7fqm-jm52-f9vc",
"modified": "2022-09-30T05:37:28Z",
"modified": "2024-10-16T21:36:40Z",
"published": "2022-09-29T00:00:19Z",
"aliases": [
"CVE-2022-3292"
@@ -9,7 +9,14 @@
"summary": "rdiffweb vulnerable to Use of Cache Containing Sensitive Information",
"details": "rdiffweb prior to version 2.4.9 is vulnerable to Use of Cache Containing Sensitive Information. Due to improper cache control, an attacker can view sensitive information even if they are not logged into an account. Version 2.4.9 contains a patch for this issue.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
}
],
"affected": [
{
@@ -45,6 +52,10 @@
"type": "PACKAGE",
"url": "https://github.com/ikus060/rdiffweb"
},
{
"type": "WEB",
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/rdiffweb/PYSEC-2022-296.yaml"
},
{
"type": "WEB",
"url": "https://huntr.dev/bounties/e9309018-e94f-4e15-b7d1-5d38b6021c5d"