CVE-2018-1000060
Sensu Core version Before 1.2.0 & before commit 46ff10023e8cbf1b6978838f47c51b20b98fe30b contains a CWE-522 vulnerability in Sensu::Utilities.redact_sensitive() that can result in sensitive configuration data (e.g. passwords) may be logged in clear-text.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.36%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Sensu, Inc. Sensu Core version Before 1.2.0 & before commit 46ff10023e8cbf1b6978838f47c51b20b98fe30b contains a CWE-522 vulnerability in Sensu::Utilities.redact_sensitive() that can result in sensitive configuration data (e.g. passwords) may be logged in clear-text. This attack appear to be exploitable via victims with configuration matching a specific pattern will observe sensitive data outputted in their service log files. This vulnerability appears to have been fixed in 1.2.1 and later, after commit 46ff10023e8cbf1b6978838f47c51b20b98fe30b.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.36% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-532
- Affected
- sensu/sensu core
- Source
- cve@mitre.org
References
- https://access.redhat.com/errata/RHSA-2018:0616Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1112Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1606Third Party Advisory
- https://github.com/sensu/sensu/issues/1804Issue Tracking, Vendor Advisory
- https://github.com/sensu/sensu/pull/1810Issue Tracking, Patch, Third Party Advisory, Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:0616Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1112Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1606Third Party Advisory
- https://github.com/sensu/sensu/issues/1804Issue Tracking, Vendor Advisory
- https://github.com/sensu/sensu/pull/1810Issue Tracking, Patch, Third Party Advisory, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.