Cross-Origin Resource Consumption Vulnerability in admin-cli

Cross-Origin Resource Consumption Vulnerability in admin-cli

CVE-2016-8627 · MEDIUM Severity

AV:N/AC:M/AU:N/C:N/I:N/A:P

admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download server log files that allows logs to be available via GET requests making them vulnerable to cross-origin attacks. An attacker could trigger the user's browser to request the log files consuming enough resources that normal server functioning could be impaired.

Learn more about our Cis Benchmark Audit For Server Software.