What the vulnerability does
01Description
Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions.
Explanation of Vulnerability in Simple Terms
REST API Log versions up to 1.7.1 expose sensitive information in outbound data transmissions. An unauthenticated attacker on the network can intercept API responses to read confidential details without modifying data or disrupting service. The vulnerability requires no user interaction and affects all installations of the affected version range.
What an attacker can do
Read sensitive information from REST API responses by intercepting network traffic.
Potential impact on your site
Confidential data (API keys, tokens, user details) may be exposed to network eavesdroppers.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities