Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Exposure of sensitive PHP information to an unauthorized control sphere in mautic/mautic images
Vulnerability Description
ImpactThis is an information disclosure vulnerability originating from PHP's base image. This vulnerability exposes the PHP version through an X-Powered-By header, which attackers could exploit to fingerprint the server and identify potential weaknesses. WorkaroundsThe mitigation requires changing the expose_php variable from "On" to "Off" in the file located at /usr/local/etc/php/php.ini.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
将系统数据暴露到未授权控制的范围
Vulnerability Title
Mautic Docker Image 安全漏洞
Vulnerability Description
Mautic Docker Image是Mautic开源的一个Mautic的Docker镜像。 Mautic Docker Image存在安全漏洞,该漏洞源于通过X-Powered-By标头暴露PHP版本,可能导致服务器指纹识别。
CVSS Information
N/A
Vulnerability Type
N/A