Information Disclosure Vulnerability in Ajenti by Ajenti
CVE-2018-1000126

7.5HIGH

Key Information:

Vendor

Ajenti

Status
Vendor
CVE Published:
13 March 2018

What is CVE-2018-1000126?

Ajenti version 2 has a vulnerability that exposes sensitive information through the web application, allowing attackers to enumerate users and systems. This weakness, located in Line 176 of the source code, provides access to crucial data within the /etc/ajenti/config.yml file. Exploitation requires network connectivity to the application, highlighting potential risks for systems running this version of Ajenti.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.