CVE-2019-10667: Infoleak
An issue was discovered in LibreNMS through 1.47. Information disclosure can occur: an attacker can fingerprint the exact code version installed and disclose local file paths.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-10667?
CVE-2019-10667 is a vulnerability discovered in LibreNMS version up to and including 1.47 that allows information disclosure.
How does CVE-2019-10667 work?
CVE-2019-10667 allows an attacker to fingerprint the exact code version installed and disclose local file paths in LibreNMS.
What is the severity of CVE-2019-10667?
CVE-2019-10667 has a severity rating of medium, with a CVSS score of 5.3.
How can information disclosure be prevented in LibreNMS?
To prevent information disclosure in LibreNMS, it is recommended to update to a patched version (1.48 or later) or apply the provided fix.
Where can I find more information about CVE-2019-10667?
More information about CVE-2019-10667 can be found at the following link: [https://www.darkmatter.ae/xen1thlabs/librenms-information-disclosure-vulnerability-xl-19-018/](https://www.darkmatter.ae/xen1thlabs/librenms-information-disclosure-vulnerability-xl-19-018/)