CVE-2023-38849: Infoleak
Published Oct 25, 2023
·Updated
An issue in tire-sales Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.
Affected Software
1 affected component
linecorp Line=13.6.1
Event History
Oct 25, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue in tire-sales Line?
The vulnerability ID is CVE-2023-38849.
2
What is the severity level of CVE-2023-38849?
The severity level of CVE-2023-38849 is high (7.5).
3
How can a remote attacker exploit CVE-2023-38849?
A remote attacker can exploit CVE-2023-38849 by sending a crafted GET request to obtain sensitive information.
4
What is the affected software version of CVE-2023-38849?
The affected software version of CVE-2023-38849 is Line v.13.6.1.
5
How can I fix CVE-2023-38849 in tire-sales Line?
To fix CVE-2023-38849, update the tire-sales Line software to a version that is not affected by the vulnerability.