Impact
An anonymous user can fetch sensitive information from the status.php endpoint.
Patches
Upgrade to 10.0.18.
Workarounds
Delete the status.php file, restrict its access, or remove any sensitive values from the name field of the active LDAP directories, mail servers authentication providers and mail receivers.
For more information
If you have any questions or comments about this advisory, mail us at [email protected].
Impact
An anonymous user can fetch sensitive information from the
status.phpendpoint.Patches
Upgrade to 10.0.18.
Workarounds
Delete the
status.phpfile, restrict its access, or remove any sensitive values from thenamefield of the active LDAP directories, mail servers authentication providers and mail receivers.For more information
If you have any questions or comments about this advisory, mail us at [email protected].