CVE-2020-29041
Summary
| CVE | CVE-2020-29041 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-01-06 21:15:00 UTC |
| Updated | 2021-01-13 19:22:00 UTC |
| Description | A misconfiguration in Web-Sesame 2020.1.1.3375 allows an unauthenticated attacker to download the source code of the application, facilitating its comprehension (code review). Specifically, JavaScript source maps were inadvertently included in the production Webpack configuration. These maps contain sources used to generate the bundle, configuration settings (e.g., API keys), and developers' comments. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sesame-system | Web-sesame | 2020.1.1.3375 | All | All | All |
| Application | Sesame-system | Web-sesame | 2020.1.1.3375 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [CVE-2020-29041] Source code vulnerability disclosure discovered in the Web-Sesame application of TIL TECHNOLOGIES - Blog BSSI | MISC | blog.bssi.fr | Exploit, Third Party Advisory |
| [CVE-2020-29041] Vulnérabilité de divulgation de code source identifiée au sein de l’application Web-Sesame de TIL TECHNOLOGIES - Blog BSSI | MISC | blog.bssi.fr | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.