CVE-2017-1000192

Source
https://cve.org/CVERecord?id=CVE-2017-1000192
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-1000192.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-1000192
Published
2017-11-17T17:29:00.257Z
Modified
2026-07-08T10:54:22.572519Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Cygnux sysPass version 2.1.7 and older is vulnerable to a Local File Inclusion in the functionality of javascript files inclusion. The attacker can read the configuration files that contain the login and password from the database, private encryption key, as well as other sensitive information.

References

Affected packages

Git / github.com/nuxsmin/syspass

Affected ranges

Type
GIT
Repo
https://github.com/nuxsmin/syspass
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:cygnux:syspass:*:*:*:*:*:*:*:*",
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.1.7"
        }
    ]
}

Affected versions

1.*
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.2.18
1.1.2.19
1.1.2.20
1.1.2.21
1.1.2.22
1.1.2.23
1.1.2.24
1.2.0.02-rc2
1.2.0.03-rc3
1.2.0.04-rc4
1.2.0.05-rc5
1.2.0.06
1.2.0.07
1.2.0.08
1.2.0.09
1.2.0.10
1.2.0.11
1.2.0.12
1.2.0.13
1.2.0.14
1.2.0.16
1.2.0.17
1.2.0.18
1.2.0.19
1.2.0.20
1.2.0.21
2.*
2.0.0.17021301
2.0.0.17021302
2.0.0.17021601
2.1.0.17022601
2.1.0.17030201
2.1.1.17030601
2.1.2.17031401
2.1.3.17031601
2.1.4.17032801
2.1.5.17041201
2.1.6.17041401
2.1.7.17042101

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-1000192.json"