github.com
https://github.com/metersphere/metersphere/commit/a23f75d93b666901fd148d834df9384f6f24cf28 CVE-2023-38494
MEDIUM
The cloud version of the MeterSphere interface leaks some sensitive data without authentication
Record summary
CVE-2023-38494 has a selected CVSS score of 5.9 (medium).
Description
MeterSphere is an open-source continuous testing platform. Prior to version 2.10.4 LTS, some interfaces of the Cloud version of MeterSphere do not have configuration permissions, and are sensitively leaked by attackers. Version 2.10.4 LTS contains a patch for this issue.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 8, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
metersphereBrowse metersphere / metersphereDefault status: unknown | CVE List | Before 2.10.4-lts | affected |
| < 2.10.4-LTS | affected |
References
2github.comConfirmation
https://github.com/metersphere/metersphere/security/advisories/GHSA-fjp5-95pv-5253