CVE-2019-3992

HIGH

ELOG < 3.1.4-57bea22 - Unauthenticated Information Disclosure via Configuration File Access

Title source: llm
STIX 2.1

Description

ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can access the server's configuration file by sending an HTTP GET request. Amongst the configuration data, the attacker may gain access to valid admin usernames and, in older versions of ELOG, passwords.

References (3)

Core 3

Scores

CVSS v3 7.5
EPSS 0.0130
EPSS Percentile 66.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200 CWE-319
Status published
Products (3)
elog_project/elog < 3.1.4-57bea22
fedoraproject/fedora 30
fedoraproject/fedora 31
Published Dec 17, 2019
Tracked Since Feb 18, 2026