Description
Information exposure vulnerability in the CIGESv2 system. A remote attacker might be able to access /vendor/composer/installed.json and retrieve all installed packages used by the application.
No analysis available yet.
Remediation
Vendor Solution
All vulnerabilities have been fixed in the new product version, CIGESv3. The manufacturer has developed a patch for those customers who have not migrated to the new version.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-27670 | Information exposure vulnerability in the CIGESv2 system. A remote attacker might be able to access /vendor/composer/installed.json and retrieve all installed packages used by the application. |
References
History
Wed, 15 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Atisoluciones
Atisoluciones ciges |
|
| CPEs | cpe:2.3:a:atisoluciones:ciges:2.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Atisoluciones
Atisoluciones ciges |
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-01T19:25:40.603Z
Reserved: 2024-03-20T11:33:49.912Z
Link: CVE-2024-2725
Updated: 2024-08-01T19:25:40.603Z
Status : Analyzed
Published: 2024-03-22T14:15:10.143
Modified: 2025-10-15T18:03:21.280
Link: CVE-2024-2725
No data.
OpenCVE Enrichment
Updated: 2025-07-12T23:06:27Z
Weaknesses
EUVD