CVE-2019-15032

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/09/2019
Last modified:
19/09/2019

Description

Pydio 6.0.8 mishandles error reporting when a directory allows unauthenticated uploads, and the remote-upload option is used with the http://localhost:22 URL. The attacker can obtain sensitive information such as the name of the user who created that directory and other internal server information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pydio:pydio:6.0.8:*:*:*:*:*:*:*