CVE-2019-6242: High severity Kentico Kentico vulnerability
DISPUTED Kentico v10.0.42 allows Global Administrators to read the cleartext SMTP Password by navigating to the SMTP configuration page. NOTE: the vendor considers this a best-practice violation but not a vulnerability. The vendor plans to fix it at a future time.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6242?
CVE-2019-6242 is considered a best-practice violation by the vendor but not a direct security vulnerability.
How can I secure Kentico version 10.0.42 regarding CVE-2019-6242?
To address CVE-2019-6242, ensure that access to the SMTP configuration page is restricted to trusted Global Administrators only.
Does CVE-2019-6242 allow unauthorized access to SMTP passwords?
CVE-2019-6242 does not inherently grant unauthorized access; it allows Global Administrators to view the cleartext SMTP password.
What is the recommended action for organizations using Kentico v10.0.42 given CVE-2019-6242?
Organizations should implement access controls and monitor Global Administrators' activity in relation to the SMTP configuration page.
When will Kentico address the issue described in CVE-2019-6242?
Kentico has indicated plans to fix the issue described in CVE-2019-6242 in a future release.