Junglewise Threat Intelligence

CVE-2018-1000126: PYSEC-2018-113 - Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumerat

CVE-2018-1000126 · Severity: info · Published 2018-03-13

Technologies: ajenti-panel (PyPI). Vendors: PyPI.

Executive brief

Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application.

Affected products

  • PyPI ajenti-panel

Related threats