SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-40600

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Exactly WWW EWWW Image Optimizer.

HIGH 7.5EPSS 2.04%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.04%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Exactly WWW EWWW Image Optimizer. It works only when debug.log is turned on.This issue affects EWWW Image Optimizer: from n/a through 7.2.0.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
2.04% probability · 80th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
ewww/image optimizer
Source
audit@patchstack.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.