CVE-2024-41264
01.08.2024, 16:15
An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method.Enginsight
Vendor | Product | Version |
---|---|---|
casbin | casdoor | 1.636.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-295 - Improper Certificate ValidationThe software does not validate, or incorrectly validates, a certificate.
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.