CVE-2020-29041

MEDIUMCVSS 5.3/10EPSS 1.35%

Last modified

CVE-2020-29041 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. A misconfiguration in Web-Sesame 2020.1.1.3375 allows an unauthenticated attacker to download the source code of the application, facilitating its comprehension (code review). Specifically, JavaScript source maps were inadvertently included in the production Webpack configuration. EPSS estimates a 1.35% chance of exploitation in the next 30 days.

Description

A misconfiguration in Web-Sesame 2020.1.1.3375 allows an unauthenticated attacker to download the source code of the application, facilitating its comprehension (code review). Specifically, JavaScript source maps were inadvertently included in the production Webpack configuration. These maps contain sources used to generate the bundle, configuration settings (e.g., API keys), and developers' comments.

Metrics

CVSS 3.1
5.3/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS Probability
1.35%

68.1th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
Sesame-SystemWeb-Sesame2020.1.1.3375

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-29041?
A misconfiguration in Web-Sesame 2020.1.1.3375 allows an unauthenticated attacker to download the source code of the application, facilitating its comprehension (code review). Specifically, JavaScript source maps were inadvertently included in the production Webpack configuration. These maps contain sources used to generate the bundle, configuration settings (e.g., API keys), and developers' comments.
How severe is CVE-2020-29041?
CVE-2020-29041 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 1.35% probability of exploitation in the next 30 days.
How do I fix CVE-2020-29041?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-29041?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST