Impact
Pardus About includes a missing authorization flaw that permits an attacker to read privileged information through the About module. This weakness is classified as CWE-862: Missing Authorization. The vulnerability originates from incorrectly configured access control security levels and allows exposure of data that should be restricted.
Affected Systems
The affected product is TUBITAK BILGEM Software Technologies Research Institute Pardus About. Versions from 1.2.1 up to but not including 1.2.5 are susceptible. Any deployment running these releases is at risk.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate impact. EPSS data is unavailable, so exploitation likelihood cannot be precisely quantified, though the flaw is limited to a web interface statically served by the application. The vulnerability is not cataloged in CISA KEV. Based on the description, the likely attack vector is a web request to the About endpoint, and exploitation requires access to the target environment; it does not appear to require privileged credentials.
OpenCVE Enrichment