Datalust Seq before 2023.2.9489 allows insertion of sensitive information into an externally accessible file or directory. This is exploitable only when external (SQL Server or PostgreSQL) metadata storage is used. Exploitation can only occur from a high-privileged user account.
References
Link Resource
https://github.com/datalust/seq-tickets/issues/1886 Issue Tracking Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-07-22T00:00:00

Updated: 2023-07-22T00:00:00

Reserved: 2023-07-13T00:00:00


Link: CVE-2023-38195

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-07-22T17:15:09.687

Modified: 2023-08-01T13:46:25.913


Link: CVE-2023-38195

JSON object: View

cve-icon Redhat Information

No data.