CVE-2023-2665Storage of Sensitive Data in a Mechanism without Access Control in Rosariosis

Severity
7.5HIGHNVD
GHSA6.5
EPSS
0.1%
top 70.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 12
Latest updateMay 19

Description

Storage of Sensitive Data in a Mechanism without Access Control in GitHub repository francoisjacquet/rosariosis prior to 11.0.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

Packagistfrancoisjacquet/rosariosis< 11.0
CVEListV5francoisjacquet/francoisjacquet_rosariosisunspecified11.0
PyPIredis/redis4.4.04.4.3+2

Patches

🔴Vulnerability Details

3
OSV
RosarioSIS Stores Sensitive Data in a Mechanism without Access Control2023-05-19
GHSA
RosarioSIS Stores Sensitive Data in a Mechanism without Access Control2023-05-19
GHSA
redis-py Race Condition vulnerability2023-03-26