Exposure of Sensitive Information to an Unauthorized Actor in francoisjacquet/rosariosis
CVE-2023-0994

7.5HIGH

Key Information:

Vendor
CVE Published:
24 February 2023

What is CVE-2023-0994?

A significant security concern has been identified in the Rosariosis plugin developed by Francoise Jacquet, which allows unauthorized actors to access sensitive information. This vulnerability affects versions of the plugin prior to 10.8.2, posing risks for users who may inadvertently expose confidential data through their GitHub repository. It is crucial for users to update to the latest version to mitigate potential threats and safeguard their information.

Affected Version(s)

francoisjacquet/rosariosis < 10.8.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

CVSS V3.0

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.