Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The HTTP and WebSocket engine components in the server in Kaazing Gateway before 4.5.3 hotfix-1, Gateway - JMS Edition before 4.0.5 hotfix-15, 4.0.6 before hotfix-4, 4.0.7, 4.0.9 before hotfix-19, 4.4.x before 4.4.2 hotfix-1, 4.5.x before 4.5.3 hotfix-1, and Gateway Community and Enterprise Editions before 5.6.0 allow remote attackers to bypass intended access restrictions and obtain sensitive information via vectors related to HTTP request handling.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Kaazing Gateway 信息泄露漏洞
Vulnerability Description
Kaazing Gateway中的HTTP and WebSocket engine组件中存在信息泄露漏洞。远程攻击者可利用该漏洞绕过访问限制并获取敏感信息。以下版本受到影响:Kaazing Gateway 4.5.3 hotfix-1之前版本;Gateway(JMS版本)4.0.5 hotfix-15之前版本,4.0.6 hotfix-4之前的4.0.6版本,4.0.7版本,4.0.9 hotfix-19之前的4.0.9版本,4.4.2 hotfix-1之前的4.4.x版本,4.5.3 hotfix-1
CVSS Information
N/A
Vulnerability Type
N/A