36 lines
1.4 KiB
JSON
Raw Normal View History

{
"id": "CVE-2024-27905",
"sourceIdentifier": "security@apache.org",
"published": "2024-02-27T15:15:07.930",
"lastModified": "2024-02-27T15:15:07.930",
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "** UNSUPPORTED WHEN ASSIGNED ** Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Aurora.\n\nAn endpoint exposing internals to unauthenticated users can be used as a \"padding oracle\" allowing an anonymous attacker to construct a valid authentication cookie. Potentially this could be combined with vulnerabilities in other components to achieve remote code execution.\n\nAs this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.\n\nNOTE: This vulnerability only affects products that are no longer supported by the maintainer.\n\n"
}
],
"metrics": {},
"weaknesses": [
{
"source": "security@apache.org",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"references": [
{
"url": "http://www.openwall.com/lists/oss-security/2024/02/27/3",
"source": "security@apache.org"
},
{
"url": "https://lists.apache.org/thread/564kbv3wqdzkscmdn2bg4vlk48qymryp",
"source": "security@apache.org"
}
]
}