Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2024-22217
Disclosure Date: August 15, 2024 (last updated September 12, 2024)
A Server-Side Request Forgery (SSRF) vulnerability in Terminalfour before 8.3.19 allows authenticated users to use specific features to access internal services including sensitive information on the server that Terminalfour runs on.
0
Attacker Value
Unknown
CVE-2023-29484
Disclosure Date: October 16, 2023 (last updated October 25, 2023)
In Terminalfour before 8.3.16, misconfigured LDAP users are able to login with an invalid password.
0
Attacker Value
Unknown
CVE-2023-23591
Disclosure Date: April 12, 2023 (last updated October 08, 2023)
The Logback component in Terminalfour before 8.3.14.1 allows OS administrators to obtain sensitive information from application server logs when debug logging is enabled. The fixed versions are 8.2.18.7, 8.2.18.2.2, 8.3.11.1, and 8.3.14.1.
0
Attacker Value
Unknown
CVE-2022-30770
Disclosure Date: May 16, 2022 (last updated November 29, 2024)
Terminalfour versions 8.3.7, 8.3.x versions prior to version 8.3.8 and r 8.2.x versions prior to version 8.2.18.5 or 8.2.18.2.1 are vulnerable to (XSS) vulnerability that could be exploited by an attacker to mislead an administrator and steal their credentials.
0