Use of Cache Containing Sensitive Information in GitHub repository ikus060/rdiffweb prior to 2.4.8.
The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.
Link | Tags |
---|---|
https://huntr.dev/bounties/e9309018-e94f-4e15-b7d1-5d38b6021c5d | third party advisory exploit |
https://github.com/ikus060/rdiffweb/commit/2406780831618405a13113377a784f3102465f40 | third party advisory patch |