CVE-2026-92759
OrtaTeknik Veri (Otomatik)
- CVSS Skoru
- 6.5
- EPSS
- —
- CWE
- CWE-522
- KEV Durumu
- Hayır
SecObserve sürüm 1.59.1'den önceki sürümler, ApiConfigurationSerializer'da bir bilgi sızıntısı zafiyeti içerir ve bu, API yapılandırma yanıtlarından basic_auth_password alanını temizlemeyi başaramaz. Salt okunur ürün üyeleri, standart REST uç noktaları aracılığıyla yapılandırılmış tarayıcı veya entegrasyon hizmet hesaplarının şifresini çözdürülmüş olarak alabilir.
Orijinal açıklama (İngilizce)
SecObserve versions before 1.59.1 contain an information disclosure vulnerability in the ApiConfigurationSerializer that fails to strip the basic_auth_password field from API configuration responses. View-only product members can retrieve the decrypted basic-auth password of configured scanner or integration service accounts through standard REST endpoints.
Referanslar
- https://github.com/SecObserve/SecObserve
- https://github.com/SecObserve/SecObserve/blob/v1.54.0/backend/application/import_observations/api/serializers.py#L103-L119
- https://github.com/SecObserve/SecObserve/issues/4799
- https://github.com/SecObserve/SecObserve/releases/tag/v1.59.1
- https://github.com/SecObserve/SecObserve/security/advisories/GHSA-r968-78vw-jj9m
- https://www.vulncheck.com/advisories/secobserve-before-1.59.1-information-disclosure-via-api-configuration
Bu CVE için henüz editoryal inceleme yapılmadı. Sadece otomatik teknik veri gösteriliyor.
