cvelist/2024/29xxx/CVE-2024-29964.json

96 lines
3.3 KiB
JSON
Raw Normal View History

2024-04-02 14:13:38 +00:00
{
2024-04-19 05:00:31 +00:00
"data_version": "4.0",
2024-04-02 14:13:38 +00:00
"data_type": "CVE",
"data_format": "MITRE",
"CVE_data_meta": {
"ID": "CVE-2024-29964",
2024-04-19 05:00:31 +00:00
"ASSIGNER": "sirt@brocade.com",
"STATE": "PUBLIC"
2024-04-02 14:13:38 +00:00
},
"description": {
"description_data": [
{
"lang": "eng",
2024-04-26 00:00:33 +00:00
"value": "\u00a0Brocade SANnav versions before v2.3.0a do not correctly set permissions on files, including docker files. An unprivileged attacker who gains access to the server can read sensitive information from these files.\n"
2024-04-19 05:00:31 +00:00
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
"cweId": "CWE-200"
}
]
}
]
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "Brocade",
"product": {
"product_data": [
{
"product_name": "Brocade SANnav",
"version": {
"version_data": [
{
2024-04-26 00:00:33 +00:00
"version_value": "not down converted",
"x_cve_json_5_version_data": {
"versions": [
{
"status": "affected",
"version": "before v2.3.0a"
}
],
"defaultStatus": "affected"
}
2024-04-19 05:00:31 +00:00
}
]
}
}
]
}
}
]
}
},
"references": {
"reference_data": [
{
"url": "https://support.broadcom.com/external/content/SecurityAdvisories/0/23249",
"refsource": "MISC",
"name": "https://support.broadcom.com/external/content/SecurityAdvisories/0/23249"
}
]
},
"generator": {
"engine": "Vulnogram 0.1.0-dev"
},
"source": {
"discovery": "UNKNOWN"
},
"impact": {
"cvss": [
{
"attackComplexity": "LOW",
2024-04-26 00:00:33 +00:00
"attackVector": "ADJACENT_NETWORK",
2024-04-19 05:00:31 +00:00
"availabilityImpact": "NONE",
2024-04-26 00:00:33 +00:00
"baseScore": 5.7,
2024-04-19 05:00:31 +00:00
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
2024-04-26 00:00:33 +00:00
"privilegesRequired": "LOW",
2024-04-19 05:00:31 +00:00
"scope": "UNCHANGED",
"userInteraction": "NONE",
2024-04-26 00:00:33 +00:00
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
2024-04-19 05:00:31 +00:00
"version": "3.1"
2024-04-02 14:13:38 +00:00
}
]
}
}