CVE-2024-22200
Published Jan 30, 2024
Last updated 9 months ago
Overview
- Description
- vantage6-UI is the User Interface for vantage6. The docker image used to run the UI leaks the nginx version. To mitigate the vulnerability, users can run the UI as an angular application. This vulnerability was patched in 4.2.0.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 5.3
- Impact score
- 1.4
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity
- MEDIUM
Weaknesses
- nvd@nist.gov
- NVD-CWE-noinfo
- security-advisories@github.com
- CWE-200
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:vantage6:vantage6-ui:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CDABDC62-80CD-4CBD-A86D-7C8A5F054290", "versionEndExcluding": "4.2.0" } ], "operator": "OR" } ] } ]