Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix severity #9762

Merged
merged 1 commit into from May 13, 2024
Merged

fix severity #9762

merged 1 commit into from May 13, 2024

Conversation

pwnhxl
Copy link
Contributor

@pwnhxl pwnhxl commented May 11, 2024

This only returns the internal network address, and Microsoft does not acknowledge that this is a vulnerability!

@ritikchaddha ritikchaddha self-assigned this May 11, 2024
@ritikchaddha ritikchaddha added the Done Ready to merge label May 11, 2024
@userdehghani
Copy link
Contributor

userdehghani commented May 12, 2024

it's not a microsoft application vulnerability but any organization can config their own on-premise ms-exchange server and the local domain exposure is a valid vulnerability on organization side.

@pwnhxl @ritikchaddha

@ritikchaddha ritikchaddha removed the Done Ready to merge label May 12, 2024
@pwnhxl
Copy link
Contributor Author

pwnhxl commented May 12, 2024

@userdehghani
In general, Microsoft assigns CVE numbers to product vulnerabilities, such as: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34473

Could you please provide the CVE number?

If the internal IP address is leaked, would that be considered a vulnerability? http/misconfiguration/internal-ip-disclosure.yaml
This template should also be used for low-risk vulnerabilities.

@userdehghani
Copy link
Contributor

userdehghani commented May 12, 2024

private information disclosure is under CWE-200, and i consider CVSS 3.1 as the basis for calculating the severity of vulnerability. the minimum severity of this vulnerability will be categorized as low.

@pwnhxl

@ritikchaddha ritikchaddha added the Done Ready to merge label May 13, 2024
@DhiyaneshGeek DhiyaneshGeek merged commit 84e24e9 into projectdiscovery:main May 13, 2024
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Done Ready to merge
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants