Intel

AIKIDO-2024-10387

opcodesio/log-viewer is vulnerable to Initialization of a Resource with an Insecure Default

Initialization of a Resource with an Insecure Default Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Oct 29, 2024

81

High Risk

This Affects:

phpopcodesio/log-viewer
1.0.0 - 3.2.0
Fixed in 3.3.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to initialization of a resource with an insecure default. The /log-viewer endpoint is accessible to all users by default, potentially exposing sensitive information stored in logs.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

opcodesio/log-viewer is vulnerable to Initialization of a Resource with an Insecure Default in versions 1.0.0 - 3.2.0.

How to fix this

Upgrade opcodesio/log-viewer library to patch version or restrict the access to LogViewer in your code.