3 results (0.002 seconds)

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 1

CloudExplorer Lite is an open source, lightweight cloud management platform. Prior to version 1.4.1, the gateway filter of CloudExplorer Lite uses a controller with path starting with `matching/API/`, which can cause a permission bypass. Version 1.4.1 contains a patch for this issue. CloudExplorer Lite es una plataforma de gestión de la nube ligera y de código abierto. Antes de la versión 1.4.1, el filtro de puerta de enlace de CloudExplorer Lite utiliza un controlador con una ruta que comienza con `matching/API/`, lo que puede provocar una omisión de permisos. • https://github.com/CloudExplorer-Dev/CloudExplorer-Lite/security/advisories/GHSA-fqxr-7g94-vrfj • CWE-287: Improper Authentication •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 1

An issue in CloudExplorer Lite 1.3.1 allows an attacker to obtain sensitive information via the login key component. Un problema en CloudExplorer Lite 1.3.1 permite a un atacante obtener información sensible a través del componente de clave de inicio de sesión. • https://www.cnblogs.com/xyhz/p/17667095.html • CWE-319: Cleartext Transmission of Sensitive Information •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 1

Cloud Explorer Lite is an open source cloud management platform. Prior to version 1.4.0, there is a risk of sensitive information leakage in the user information acquisition of CloudExplorer Lite. The vulnerability has been fixed in version 1.4.0. • https://github.com/CloudExplorer-Dev/CloudExplorer-Lite/releases/tag/v1.4.0 https://github.com/CloudExplorer-Dev/CloudExplorer-Lite/security/advisories/GHSA-hh2g-77xq-x4vq • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •