FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10, an endpoint intended to offer limited enumeration abilities to authenticated users was accessible to unauthenticated users. This enabled unauthenticated users to discover files and their respective paths that were visible to the Apache user group. Version 1.5.10 contains a patch for this issue.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2023-10-31T14:59:37.088Z

Updated: 2024-09-05T17:39:26.525Z

Reserved: 2023-10-19T20:34:00.947Z

Link: CVE-2023-46237

cve-icon Vulnrichment

Updated: 2024-08-02T20:37:40.266Z

cve-icon NVD

Status : Analyzed

Published: 2023-10-31T15:15:09.707

Modified: 2023-11-08T17:41:11.243

Link: CVE-2023-46237

cve-icon Redhat

No data.