CVE-2022-27893
MEDIUMOsisoft-pi-web-connector < 0.44.0 - Log Information Exposure
Title source: ruleDescription
The Foundry Magritte plugin osisoft-pi-web-connector versions 0.15.0 - 0.43.0 was found to be logging in a manner that captured authentication requests. This vulnerability is resolved in osisoft-pi-web-connector version 0.44.0.
References (1)
Core 1
Core References
Scores
CVSS v3
4.2
EPSS
0.0006
EPSS Percentile
17.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-532
Status
published
Products (1)
osisoft-pi-web-connector_project/osisoft-pi-web-connector
0.15.0 - 0.44.0
Published
Nov 04, 2022
Tracked Since
Feb 18, 2026