Security Advisory

CVE-2019-15032

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-09-19 16:03:06
Last updated 2024-08-05 00:34:53
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Pydio 6.0.8 mishandles error reporting when a directory allows unauthenticated uploads, and the remote-upload option is used with the http://localhost:22 URL. The attacker can obtain sensitive information such as the name of the user who created that directory and other internal server information.