CVE-2019-13348

HIGH

Knowage < 6.4 - Authenticated Cleartext Credential Exposure via Datasources Page

Title source: llm
STIX 2.1

Description

In Knowage through 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source credentials in cleartext, which includes databases.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://blog.contentsecurity.com.au/knowage-password-disclosure

Scores

CVSS v3 8.8
EPSS 0.0147
EPSS Percentile 70.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-522
Status published
Products (1)
eng/knowage < 6.4
Published Aug 28, 2019
Tracked Since Feb 18, 2026