CVE-2020-18972Resource Exposure in Project Podofo

CWE-668Resource Exposure4 documents4 sources
Severity
5.5MEDIUMNVD
EPSS
0.2%
top 62.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 25
Latest updateMay 24

Description

Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allows attackers to obtain sensitive information via 'IsNextToken' in the component 'src/base/PdfToenizer.cpp'.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-x4h7-rg57-2fqw: Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v02022-05-24
OSV
CVE-2020-18972: Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v02021-08-25

📋Vendor Advisories

1
Debian
CVE-2020-18972: libpodofo - Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allo...2020
CVE-2020-18972 — Resource Exposure in Project Podofo | cvebase