aria2c in aria2 1.33.1, when --log is used, can store an HTTP Basic Authentication username and password in a file, which might allow local users to obtain sensitive information by reading this file.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade aria2 | Feb 15, 2019 | Jan 2, 2019 |
| Debian | — | Upgrade aria2 | Feb 14, 2019 | Jan 2, 2019 |
| Suse | — | Upgrade aria2-develUpgrade aria2-langUpgrade libaria2-0Upgrade aria2 | Jan 14, 2019 | Jan 2, 2019 |
| Ubuntu | — | Upgrade aria2 (Ubuntu Pro)Upgrade aria2Upgrade libaria2-0 | May 7, 2019 | Jan 2, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub