CVE-2020-15235

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
05/10/2020
Last modified:
19/10/2020

Description

In RACTF before commit f3dc89b, unauthenticated users are able to get the value of sensitive config keys that would normally be hidden to everyone except admins. All versions after commit f3dc89b9f6ab1544a289b3efc06699b13d63e0bd(3/10/20) are patched.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ractf:core:*:*:*:*:*:*:*:* 41edf92 (including)