CVE-2020-29041
Last modified
CVE-2020-29041 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. A misconfiguration in Web-Sesame 2020.1.1.3375 allows an unauthenticated attacker to download the source code of the application, facilitating its comprehension (code review). Specifically, JavaScript source maps were inadvertently included in the production Webpack configuration. EPSS estimates a 1.35% chance of exploitation in the next 30 days.
Description
A misconfiguration in Web-Sesame 2020.1.1.3375 allows an unauthenticated attacker to download the source code of the application, facilitating its comprehension (code review). Specifically, JavaScript source maps were inadvertently included in the production Webpack configuration. These maps contain sources used to generate the bundle, configuration settings (e.g., API keys), and developers' comments.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sesame-System | Web-Sesame | 2020.1.1.3375 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-29041?
How severe is CVE-2020-29041?
How do I fix CVE-2020-29041?
Are you affected by CVE-2020-29041?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
