Description
ELOG 3.1.4-57bea22 and below can be used as an HTTP GET request proxy when unauthenticated remote attackers send crafted HTTP POST requests.
References (3)
Scores
CVSS v3
6.5
EPSS
0.0350
EPSS Percentile
87.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Details
CWE
CWE-441
CWE-610
Status
published
Products (3)
elog_project/elog
< 3.1.4-57bea22
fedoraproject/fedora
30
fedoraproject/fedora
31
Published
Dec 17, 2019
Tracked Since
Feb 18, 2026