UBUNTU-CVE-2019-3992

Source
https://ubuntu.com/security/CVE-2019-3992
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-3992.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2019-3992
Upstream
  • CVE-2019-3992
Published
2019-12-17T22:15:00Z
Modified
2025-10-24T04:47:27Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can access the server's configuration file by sending an HTTP GET request. Amongst the configuration data, the attacker may gain access to valid admin usernames and, in older versions of ELOG, passwords.

References

Affected packages

Ubuntu:16.04:LTS / elog

Package

Name
elog
Purl
pkg:deb/ubuntu/elog@3.1.1-1-1?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.1.0-2-1
3.1.1-1-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "elog",
            "binary_version": "3.1.1-1-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-3992.json"

Ubuntu:18.04:LTS / elog

Package

Name
elog
Purl
pkg:deb/ubuntu/elog@3.1.3-1-1build1?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.1.3-1-1
3.1.3-1-1build1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "elog",
            "binary_version": "3.1.3-1-1build1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-3992.json"

Ubuntu:20.04:LTS / elog

Package

Name
elog
Purl
pkg:deb/ubuntu/elog@3.1.3-1-1build1?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.1.3-1-1build1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "elog",
            "binary_version": "3.1.3-1-1build1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-3992.json"

Ubuntu:22.04:LTS / elog

Package

Name
elog
Purl
pkg:deb/ubuntu/elog@3.1.3-1-1build2?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.1.3-1-1build1
3.1.3-1-1build2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "elog",
            "binary_version": "3.1.3-1-1build2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-3992.json"