CVE-2019-1692
published 2019-05-03CVE-2019-1692: A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated…
PriorityP431medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
1.20%
64.9th percentile
A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, remote attacker to access sensitive system usage information. The vulnerability is due to a lack of proper data protection mechanisms for certain components in the underlying Application Centric Infrastructure (ACI). An attacker could exploit this vulnerability by attempting to observe certain network traffic when accessing the APIC. A successful exploit could allow the attacker to access and collect certain tracking data and usage statistics on an affected device.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | application_policy_infrastructure_controller | < 4.1\(1i\) | 4.1\(1i\) |
| cisco | application_policy_infrastructure_controller | — | — |
| cisco | application_policy_infrastructure_controller_web-based | — | — |
| cisco | cisco_application_policy_infrastructure_controller | >= unspecified < 4.1(1i) | 4.1(1i) |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q7p6-jrrp-5975: A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthentic
ghsa_unreviewed·2022-05-24
CVE-2019-1692 [MEDIUM] GHSA-q7p6-jrrp-5975: A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthentic
A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, remote attacker to access sensitive system usage information. The vulnerability is due to a lack of proper data protection mechanisms for certain components in the underlying Application Centric Infrastructure (ACI). An attacker could exploit this vulnerability by attempting to observe certain network traffic when accessing the APIC. A successful exploit could allow the attacker to access and collect certain tracking data and usage statistics on an affected device.
Cisco
Cisco Application Policy Infrastructure Controller Web-Based Management Interface Usage Information Disclosure Vulnerability
vendor_cisco·2019-05-01·CVSS 5.3
CVE-2019-1692 [MEDIUM] CWE-311 Cisco Application Policy Infrastructure Controller Web-Based Management Interface Usage Information Disclosure Vulnerability
Cisco Application Policy Infrastructure Controller Web-Based Management Interface Usage Information Disclosure Vulnerability
A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, remote attacker to access sensitive system usage information.
The vulnerability is due to a lack of proper data protection mechanisms for certain components in the underlying Application Centric Infrastructure (ACI). An attacker could exploit this vulnerability by attempting to observe certain network traffic when accessing the APIC. A successful exploit could allow the attacker to access and collect certain tracking data and usage statistics on an affected device.
There are no workarounds that address this vulne
Cisco
Cisco Application Policy Infrastructure Controller Web-Based Management Interface Usage Information Disclosure Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1692 Cisco Application Policy Infrastructure Controller Web-Based Management Interface Usage Information Disclosure Vulnerability
CVE-2019-1692: Cisco Application Policy Infrastructure Controller Web-Based Management Interface Usage Information Disclosure Vulnerability
A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, remote attacker to access sensitive system usage information. The vulnerability is due to a lack of proper data protection mechanisms for certain components in the underlying Application Centric Infrastructure (ACI). An attacker could exploit this vulnerability by attempting to observe certain network traffic when accessing the APIC. A successful exploit could allow the attacker to access and collect certain tracking data and usage statistics on an affected device. There are no
CVSS: 3.0
CWE: CWE-31
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-3850 moodle: Stored HTML in assignment submission comments allowed links to be opened directly
bugzilla·2019-03-26·CVSS 4.3
CVE-2019-3850 [MEDIUM] CVE-2019-3850 moodle: Stored HTML in assignment submission comments allowed links to be opened directly
CVE-2019-3850 moodle: Stored HTML in assignment submission comments allowed links to be opened directly
A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Links within assignment submission comments would open directly (in the same window). Although links themselves may be valid, opening within the same window and without the no-referrer header policy made them more susceptible to exploits.
Upstream Bug:
https://tracker.moodle.org/browse/MDL-64651
Upstream Patch:
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-64651
Discussion:
Acknowledgments:
Name: Steeven George
---
External References:
https://moodle.org/mod/forum/discuss.php?d=384013#p1547745
---
Created moodle tracking bugs for this issue:
Affects: epel-all [bug 1692
Bugzilla
CVE-2019-3848 moodle: Logged in users could view all calendar events
bugzilla·2019-03-26·CVSS 4.3
CVE-2019-3848 [MEDIUM] CVE-2019-3848 moodle: Logged in users could view all calendar events
CVE-2019-3848 moodle: Logged in users could view all calendar events
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logged in non-guest users could view unauthorised calendar events. (Note: It was read-only access, users could not edit the events.)
Upstream Bug:
https://tracker.moodle.org/browse/MDL-64830
Upstream Patch:
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-64830
Discussion:
Acknowledgments:
Name: Juan Leyva
---
External References:
https://moodle.org/mod/forum/discuss.php?d=384011#p1547743
---
Created moodle tracking bugs for this issue:
Affects: epel-all [bug 1692906]
Affects: fedora-all [bug 1692
Bugzilla
CVE-2019-6133 polkit: Temporary auth hijacking via PID reuse and non-atomic fork
bugzilla·2019-01-08·CVSS 6.7
CVE-2019-6133 [MEDIUM] CVE-2019-6133 polkit: Temporary auth hijacking via PID reuse and non-atomic fork
CVE-2019-6133 polkit: Temporary auth hijacking via PID reuse and non-atomic fork
polkit has a vulnerability that allows a local attacker to hijack a PID during an authentication attempt by a non-root user and subsequently execute code as the authenticated process.
Upstream patch:
https://gitlab.freedesktop.org/polkit/polkit/commit/c898fdf4b1aafaa04f8ada9d73d77c8bb76e2f81
https://gitlab.freedesktop.org/polkit/polkit/merge_requests/19
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=7b55851367136b1efd84d98fea81ba57a98304cf
Discussion:
Acknowledgments:
Name: Jan Rybar (freedesktop.org)
Upstream: Jann Horn (Google Project Zero)
---
External References:
https://bugs.chromium.org/p/project-zero/issues/detail?id=1692
---
Upstream bug:
https://gitlab.freede
2019-05-03
Published