LabKey.Server.visualization-export.Information.Disclosure

description-logoDescription

This indicates an attack attempt against an Information Disclosure vulnerability in LabKey Server.
The vulnerabilities is due to an error in the application when handling a crafted svg or xml file. A remote attacker can exploit this by injecting an XXE payload to gain unauthorized access to sensitive information.

affected-products-logoAffected Products

LabKey Server 19.1.0

Impact logoImpact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.

recomended-action-logoRecommended Actions

Currently, we are unaware of any vendor-supplied patch or updates available for this issue.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2024-04-11 27.765 Default_action:pass:drop
2024-04-02 27.759