CVE-2021-38712
HIGHOneNav 0.9.12 - Info Disclosure
Title source: llmDescription
OneNav 0.9.12 allows Information Disclosure of the onenav.db3 contents. NOTE: the vendor's recommended solution is to block the access via an NGINX configuration file.
Scores
CVSS v3
7.5
EPSS
0.0024
EPSS Percentile
46.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-668
Status
published
Affected Products (1)
onenav/onenav
Timeline
Published
Aug 16, 2021
Tracked Since
Feb 18, 2026