Landscape's Apache server-status is accessible by default
CVE-2023-32550
8.2HIGH
Summary
The Landscape product by Canonical is vulnerable due to its server-status page inadvertently disclosing sensitive system information. This vulnerability can be exploited through GET requests, potentially exposing further details from the Landscape API and facilitating additional attacks. Administrators should take immediate steps to restrict access to the server-status page to mitigate risks associated with this data leak.
Affected Version(s)
Landscape Linux 0 < 19.10.05
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Anton Ivanov