CVE-2018-1000126: Infoleak
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1000126?
CVE-2018-1000126 is classified as having a moderate severity due to its potential for information disclosure.
How do I fix CVE-2018-1000126?
To fix CVE-2018-1000126, you should update Ajenti to the latest version that has addressed this vulnerability.
Who is affected by CVE-2018-1000126?
Any user or system running Ajenti version 2 is potentially affected by CVE-2018-1000126.
What kind of data can be disclosed because of CVE-2018-1000126?
CVE-2018-1000126 can disclose user and system enumeration information as well as contents from the /etc/ajenti/config.yml file.
Is CVE-2018-1000126 exploitable remotely?
Yes, CVE-2018-1000126 is exploitable via network connectivity to the affected Ajenti web application.