Impact
A vulnerability in MineAdmin versions 1.x and 2.x allows remote attackers to manipulate an unspecified feature of the Swagger component, resulting in the disclosure of sensitive information. The flaw can be exploited without authentication, and an exploit has been publicly released for this issue.
Affected Systems
The vulnerability affects MineAdmin, specifically version 1.0 and 2.0, as identified by the vendor and listed in the CVE. Users running these versions are at risk if the Swagger interface remains accessible.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, while the EPSS score of less than 1% suggests low probability of exploitation at the present time. The vulnerability is not currently included in the CISA KEV catalog, but remote attackers can still leverage the disclosed information by accessing exposed Swagger endpoints. Due to the lack of a vendor patch and the remote attack vector, administrators should treat this disclosure as a potential threat to confidentiality.
OpenCVE Enrichment
Github GHSA