CVE-2024-6060
CVE-2024-6060
9.3
CriticalPublished:
Last updated:
Source:103e4ec9-0a87-450b-af77-479448ddef11
Deferred
Weakness (CWE)
CVSS Vector
v4.0- Attack Vector
- Local
- Attack Complexity
- Low
- Attack Requirements
- None
- Privileges Required
- None
- User Interaction
- Passive
- Confidentiality (Vulnerable)
- High
- Integrity (Vulnerable)
- High
- Availability (Vulnerable)
- Low
- Confidentiality (Subsequent)
- High
- Integrity (Subsequent)
- High
- Availability (Subsequent)
- Low
Description
An information disclosure vulnerability in Phloc Webscopes 7.0.0 allows local attackers with access to the log files to view logged HTTP requests that contain user passwords or other sensitive information.
References
103e4ec9-0a87-450b-af77-479448ddef11
https://www.sonatype.com/security-advisories/cve-2024-6060af854a3a-2127-422b-91ae-364da2661108
https://sites.google.com/sonatype.com/vulnerabilities/cve-2024-6060