CVE-2020-14337 Information
Feb 14, 2021
cve
Description
A data exposure flaw was found in Tower where sensitive data was revealed from the HTTP return error codes. This flaw allows an unauthenticated remote attacker to retrieve pages from the default organization and verify existing usernames. The highest threat from this vulnerability is to data confidentiality.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Reference
https://bugzilla.redhat.com/show_bug.cgi?id=1859139
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
5.8
Share on: