Intel

AIKIDO-2024-10387

opcodesio/log-viewer is vulnerable to Initialization of a Resource with an Insecure Default

Initialization of a Resource with an Insecure Default Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Oct 29, 2024

81

High Risk

This Affects:

phpopcodesio/log-viewer
1.0.0 - 3.2.0
Fixed in 3.3.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to initialization of a resource with an insecure default. The /log-viewer endpoint is accessible to all users by default, potentially exposing sensitive information stored in logs.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

opcodesio/log-viewer is vulnerable to Initialization of a Resource with an Insecure Default in versions 1.0.0 - 3.2.0.

How to fix this

Upgrade opcodesio/log-viewer library to patch version or restrict the access to LogViewer in your code.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform