CVE-2022-45895

MEDIUM

Planet eStream < 6.72.10.07 - Sensitive Information Exposure via ON Cookie and WhoAmI Endpoint

Title source: llm
STIX 2.1

Description

Planet eStream before 6.72.10.07 discloses sensitive information, related to the ON cookie (findable in HTML source code for Default.aspx in some situations) and the WhoAmI endpoint (e.g., path disclosure).

Scores

CVSS v3 6.5
EPSS 0.0073
EPSS Percentile 49.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-668
Status published
Products (1)
planetestream/planet_estream < 6.72.10.07
Published Dec 25, 2022
Tracked Since Feb 18, 2026