pcapture is an open source dumpcap web service interface . In affected versions this vulnerability allows an authenticated but unprivileged user to use the REST API to capture and download packets with no capture filter and without adequate permissions. This is important because the capture filters can effectively limit the scope of information that a user can see in the data captures. If no filter is present, then all data on the local network segment where the program is running can be captured and downloaded. v3.12 fixes this problem. There is no workaround, you must upgrade to v3.12 or greater.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2021-09-07T18:55:11
Updated: 2024-08-04T01:58:18.288Z
Reserved: 2021-08-16T00:00:00
Link: CVE-2021-39196
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2021-09-07T19:15:08.677
Modified: 2022-08-05T10:55:09.787
Link: CVE-2021-39196
Redhat
No data.