Description
A vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows an attacker to access sensitive information stored in cleartext inside cookies via certain widely-available tools. QNAP have already fixed this vulnerability in the following versions: QTS 4.5.1.1456 build 20201015 (and later) QuTS hero h4.5.1.1472 build 20201031 (and later) QuTScloud c4.5.2.1379 build 20200730 (and later)
No analysis available yet.
Remediation
Vendor Solution
QNAP have already fixed this vulnerability in the following versions: QTS 4.5.1.1456 build 20201015 (and later) QuTS hero h4.5.1.1472 build 20201031 (and later) QuTScloud c4.5.2.1379 build 20200730 (and later)
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-11612 | A vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows an attacker to access sensitive information stored in cleartext inside cookies via certain widely-available tools. QNAP have already fixed this vulnerability in the following versions: QTS 4.5.1.1456 build 20201015 (and later) QuTS hero h4.5.1.1472 build 20201031 (and later) QuTScloud c4.5.2.1379 build 20200730 (and later) |
References
| Link | Providers |
|---|---|
| https://www.qnap.com/zh-tw/security-advisory/qsa-20-23 |
|
History
No history.
Status: PUBLISHED
Assigner: qnap
Published:
Updated: 2024-09-16T23:50:48.219Z
Reserved: 2018-12-07T00:00:00.000Z
Link: CVE-2018-19941
No data.
Status : Modified
Published: 2020-12-31T17:15:12.320
Modified: 2024-11-21T03:58:51.163
Link: CVE-2018-19941
No data.
OpenCVE Enrichment
No data.
EUVD