CVE-2020-10871: Infoleak
DISPUTED In OpenWrt LuCI git-20.x, remote unauthenticated attackers can retrieve the list of installed packages and services. NOTE: the vendor disputes the significance of this report because, for instances reachable by an unauthenticated actor, the same information is available in other (more complex) ways, and there is no plan to restrict the information further.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-10871?
CVE-2020-10871 is a vulnerability in OpenWrt LuCI git-20.x that allows remote unauthenticated attackers to retrieve the list of installed packages and services.
What is the severity of CVE-2020-10871?
CVE-2020-10871 has a severity rating of medium with a severity value of 5.3.
How can remote unauthenticated attackers exploit CVE-2020-10871?
Remote unauthenticated attackers can exploit CVE-2020-10871 to retrieve the list of installed packages and services in OpenWrt LuCI git-20.x.
Is there a fix for CVE-2020-10871?
Currently, there is no available fix for CVE-2020-10871. It is recommended to follow the vendor's updates and security advisories for any patches or mitigations.
Where can I find more information about CVE-2020-10871?
You can find more information about CVE-2020-10871 on the following references: [link 1](https://github.com/openwrt/luci/issues/3563#issuecomment-578522860), [link 2](https://github.com/openwrt/luci/issues/3653#issue-567892007), [link 3](https://github.com/openwrt/luci/issues/3766).