CVE-2024-42349: FOG has a Log Information Disclosure
FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.4 and earlier can leak authorized and rejected logins via logs stored directly on the root of the web server. FOG Server creates 2 logs on the root of the web server (fogloginaccepted.log and fogloginfailed.log), exposing the name of the user account used to manage FOG, the IP address of the computer used to login and the User-Agent. This vulnerability is fixed in 1.5.10.47.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42349?
CVE-2024-42349 is considered a medium severity vulnerability due to the potential for exposure of sensitive login information.
How do I fix CVE-2024-42349?
To fix CVE-2024-42349, upgrade FOG Server to version 1.5.10.47 or later to ensure that logs are not improperly exposed.
What types of data are exposed in CVE-2024-42349?
CVE-2024-42349 may expose both authorized and rejected login attempts due to insecure log file handling.
Which versions of FOG Server are affected by CVE-2024-42349?
FOG Server versions 1.5.10.41.4 and earlier are impacted by CVE-2024-42349.
Where are the logs affected by CVE-2024-42349 stored?
The logs affected by CVE-2024-42349 are stored directly on the root of the web server.