First published: Mon Sep 09 2019(Updated: )
An issue was discovered in LibreNMS through 1.47. Information disclosure can occur: an attacker can fingerprint the exact code version installed and disclose local file paths.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Librenms Librenms | <=1.47 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10667 is a vulnerability discovered in LibreNMS version up to and including 1.47 that allows information disclosure.
CVE-2019-10667 allows an attacker to fingerprint the exact code version installed and disclose local file paths in LibreNMS.
CVE-2019-10667 has a severity rating of medium, with a CVSS score of 5.3.
To prevent information disclosure in LibreNMS, it is recommended to update to a patched version (1.48 or later) or apply the provided fix.
More information about CVE-2019-10667 can be found at the following link: [https://www.darkmatter.ae/xen1thlabs/librenms-information-disclosure-vulnerability-xl-19-018/](https://www.darkmatter.ae/xen1thlabs/librenms-information-disclosure-vulnerability-xl-19-018/)