Sphinxsearch Sphinx 3.1.1

CPE Details

Sphinxsearch Sphinx 3.1.1
3.1.1
2019-08-26
10h25 +00:00
2019-08-26
10h25 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:sphinxsearch:sphinx:3.1.1:*:*:*:*:*:*:*

Informations

Vendor

sphinxsearch

Product

sphinx

Version

3.1.1

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2020-29050 2022-01-07 05h02 +00:00 SphinxSearch in Sphinx Technologies Sphinx through 3.1.1 allows directory traversal (in conjunction with CVE-2019-14511) because the mysql client can be used for CALL SNIPPETS and load_file operations on a full pathname (e.g., a file in the /etc directory). NOTE: this is unrelated to CMUSphinx.
7.5
High
CVE-2019-14511 2019-08-22 10h26 +00:00 Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it exposed to the internet (unless filtered by a firewall or reconfigured to listen to 127.0.0.1 only).
7.5
High