Vulnerabilities > CVE-2021-38712 - Exposure of Resource to Wrong Sphere vulnerability in Onenav 0.9.12

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
onenav
CWE-668

Summary

OneNav 0.9.12 allows Information Disclosure of the onenav.db3 contents. NOTE: the vendor's recommended solution is to block the access via an NGINX configuration file.

Vulnerable Configurations

Part Description Count
Application
Onenav
1

Common Weakness Enumeration (CWE)