cvelist/2023/32xxx/CVE-2023-32283.json

86 lines
2.8 KiB
JSON
Raw Normal View History

2023-05-06 03:00:36 +00:00
{
2023-11-14 20:00:38 +00:00
"data_version": "4.0",
2023-05-06 03:00:36 +00:00
"data_type": "CVE",
"data_format": "MITRE",
"CVE_data_meta": {
"ID": "CVE-2023-32283",
2023-11-14 20:00:38 +00:00
"ASSIGNER": "secure@intel.com",
"STATE": "PUBLIC"
2023-05-06 03:00:36 +00:00
},
"description": {
"description_data": [
{
"lang": "eng",
2023-11-14 20:00:38 +00:00
"value": "Insertion of sensitive information into log file in some Intel(R) On Demand software before versions 1.16.2, 2.1.1, 3.1.0 may allow an authenticated user to potentially enable information disclosure via local access."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "information disclosure"
},
{
"lang": "eng",
"value": "Insertion of sensitive information into log file",
"cweId": "CWE-532"
}
]
}
]
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "n/a",
"product": {
"product_data": [
{
"product_name": "Intel(R) On Demand software",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "before versions 1.16.2, 2.1.1, 3.1.0"
}
]
}
}
]
}
}
]
}
},
"references": {
"reference_data": [
{
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00914.html",
"refsource": "MISC",
"name": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00914.html"
}
]
},
"impact": {
"cvss": [
{
"version": "3.1",
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
2023-05-06 03:00:36 +00:00
}
]
}
}