Vulnerabilities > CVE-2022-38668 - Use of Uninitialized Resource vulnerability in Crowcpp Crow 1.0+4

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
crowcpp
CWE-908

Summary

HTTP applications (servers) based on Crow through 1.0+4 may reveal potentially sensitive uninitialized data from stack memory when fulfilling a request for a static file smaller than 16 KB.

Vulnerable Configurations

Part Description Count
Application
Crowcpp
1

Common Weakness Enumeration (CWE)