← back
CVE-2023-1974highCWE-1230

Exposure of Sensitive Information Through Metadata in answerdev/answer

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.7epss 0.6%
exploitation probability
0.6%top 55% of all CVEs
observed exploitation
nono source reports it
In short

The Answer application before version 1.0.8 leaks sensitive information through file metadata, allowing unauthorized users to discover details that should remain hidden. This can expose configuration data, internal paths, or other confidential information embedded in files.

Technical detail

CWE-1230 describes improper exposure of sensitive information through metadata in file systems or archives. In answer prior to 1.0.8, metadata attributes (timestamps, internal identifiers, or embedded comments) in served files may be accessible to unauthenticated attackers, leading to information disclosure without requiring special privileges or user interaction.

Summary generated and translated by AI from the official description.
Exposure of Sensitive Information Through Metadata in GitHub repository answerdev/answer prior to 1.0.8.
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H