CVE-2014-125056
A vulnerability was found in Pylons horus and classified as problematic.
Does this matter?
Lower severity and a low EPSS score (0.69%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was found in Pylons horus and classified as problematic. Affected by this issue is some unknown functionality of the file horus/flows/local/services.py. The manipulation leads to observable timing discrepancy. The complexity of an attack is rather high. The exploitation is known to be difficult. The patch is identified as fd56ccb62ce3cbdab0484fe4f9c25c4eda6c57ec. It is recommended to apply a patch to fix this issue. VDB-217598 is the identifier assigned to this vulnerability.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.69% probability · 51th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-208
- Affected
- pylonsproject/horus
- Source
- cna@vuldb.com
References
- https://github.com/Pylons/horus/commit/fd56ccb62ce3cbdab0484fe4f9c25c4eda6c57ecPatch, Third Party Advisory
- https://vuldb.com/?ctiid.217598Third Party Advisory, VDB Entry
- https://vuldb.com/?id.217598Third Party Advisory, VDB Entry
- https://github.com/Pylons/horus/commit/fd56ccb62ce3cbdab0484fe4f9c25c4eda6c57ecPatch, Third Party Advisory
- https://vuldb.com/?ctiid.217598Third Party Advisory, VDB Entry
- https://vuldb.com/?id.217598Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.