CVE-2022-45895

MEDIUM

Planetestream Planet Estream < 6.72.10.07 - Exposure to Wrong Actor

Title source: rule

Description

Planet eStream before 6.72.10.07 discloses sensitive information, related to the ON cookie (findable in HTML source code for Default.aspx in some situations) and the WhoAmI endpoint (e.g., path disclosure).

Scores

CVSS v3 6.5
EPSS 0.0034
EPSS Percentile 56.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-668
Status published

Affected Products (1)

planetestream/planet_estream < 6.72.10.07

Timeline

Published Dec 25, 2022
Tracked Since Feb 18, 2026