Datalust Seq before 2023.2.9489 allows insertion of sensitive information into an externally accessible file or directory. This is exploitable only when external (SQL Server or PostgreSQL) metadata storage is used. Exploitation can only occur from a high-privileged user account.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-42017 | Datalust Seq before 2023.2.9489 allows insertion of sensitive information into an externally accessible file or directory. This is exploitable only when external (SQL Server or PostgreSQL) metadata storage is used. Exploitation can only occur from a high-privileged user account. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://github.com/datalust/seq-tickets/issues/1886 |
|
History
Thu, 24 Oct 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-24T15:53:37.385Z
Reserved: 2023-07-13T00:00:00
Link: CVE-2023-38195
Updated: 2024-08-02T17:30:14.193Z
Status : Modified
Published: 2023-07-22T17:15:09.687
Modified: 2024-11-21T08:13:03.473
Link: CVE-2023-38195
No data.
OpenCVE Enrichment
No data.
EUVD