Information Disclosure Vulnerability in FreedomBox by FreedomBox Team
CVE-2020-25073

5.3MEDIUM

Key Information:

Vendor

Debian

Vendor
CVE Published:
2 September 2020

What is CVE-2020-25073?

FreedomBox versions up to 20.13 are affected by a vulnerability that allows remote attackers to access sensitive information via the Apache HTTP Server's /server-status page. The issue arises when connections from the Tor onion service or PageKite are incorrectly recognized as local connections, potentially exposing critical server details. This vulnerability affects both the freedombox and plinth packages across various Linux distributions, contingent upon the Apache mod_status module being enabled, thereby increasing the risk for users who have not properly secured their server configurations.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.