VulnerabilityModified
CVE-2020-15235
In RACTF before commit f3dc89b, unauthenticated users are able to get the value of sensitive config keys that would normally be hidden to everyone except admins.
HIGH 7.5EPSS 1.02%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.02%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In RACTF before commit f3dc89b, unauthenticated users are able to get the value of sensitive config keys that would normally be hidden to everyone except admins. All versions after commit f3dc89b9f6ab1544a289b3efc06699b13d63e0bd(3/10/20) are patched.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.02% probability · 61th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ractf/core
- Source
- security-advisories@github.com
References
- https://github.com/ractf/core/commit/f3dc89b9f6ab1544a289b3efc06699b13d63e0bdPatch, Vendor Advisory
- https://github.com/ractf/core/security/advisories/GHSA-ph67-c355-52vmVendor Advisory
- https://github.com/ractf/core/commit/f3dc89b9f6ab1544a289b3efc06699b13d63e0bdPatch, Vendor Advisory
- https://github.com/ractf/core/security/advisories/GHSA-ph67-c355-52vmVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.