Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it exposed to the internet (unless filtered by a firewall or reconfigured to listen to 127.0.0.1 only).
References
Configurations
Information
Published : 2019-08-22 06:15
Updated : 2019-09-13 21:15
NVD link : CVE-2019-14511
Mitre link : CVE-2019-14511
JSON object : View
CWE
CWE-306
Missing Authentication for Critical Function
Products Affected
sphinxsearch
- sphinx