CVE-2019-10137 Vulnerability Details

  /     /     /  

CVE-2019-10137 Metadata Quick Info

CVE Published: 02/07/2019 | CVE Updated: 04/08/2024 | CVE Year: 2019
Source: redhat | Vendor: spacewalkproject | Product: spacewalk-proxy
Status : PUBLISHED

CVE-2019-10137 Description

A path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached client tokens. A remote, unauthenticated attacker could use this flaw to test the existence of arbitrary files, if they have access to the proxy\'s filesystem, or can execute arbitrary code in the context of the httpd process.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-22
CWE Name: CWE-22
Source: spacewalkproject

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).