Exposure of Sensitive Information Through Metadata
CVE-2023-1974
Summary
Exposure of Sensitive Information through Metadata in the package github.com/answerdev/answer versions prior to v1.0.8 and v1.1.0-beta.1. This has the same fix as CVE-2023-1975.
- LOW
- NETWORK
- NONE
- UNCHANGED
- REQUIRED
- NONE
- HIGH
- NONE
CWE-1230 - Exposure of Sensitive Information Through Metadata
The product prevents direct access to a resource containing sensitive information, but it does not sufficiently limit access to metadata that is derived from the original, sensitive information.
References
Advisory Timeline
- Published