Logsign Unified SecOps Platform Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Logsign Unified SecOps Platform. Authentication is required to exploit this vulnerability. The specific flaw exists within the get_response_json_result endpoint. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of root. Was ZDI-CAN-24680.
History

Wed, 07 Aug 2024 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Logsign
Logsign unified Secops Platform
CPEs cpe:2.3:a:logsign:unified_secops_platform:6.4.11:*:*:*:*:*:*:*
Vendors & Products Logsign
Logsign unified Secops Platform
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Wed, 07 Aug 2024 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published: 2024-08-06T15:47:49.467Z

Updated: 2024-08-07T13:34:22.057Z

Reserved: 2024-08-06T15:47:33.796Z

Link: CVE-2024-7564

cve-icon Vulnrichment

Updated: 2024-08-07T13:33:54.616Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-06T16:15:51.000

Modified: 2024-08-07T19:59:36.240

Link: CVE-2024-7564

cve-icon Redhat

No data.