Open port leads to information disclosure
Low
W
Weblate
Submitted None
Actions:
Reported by
str33
Vulnerability Details
Technical details and impact analysis
Open port 10022 leads to disclosure of open-ssh version and current Debian version being used.
POC-
1. I performed an nmap scan ( nmap -A -T4 -p- weblate.org)
2. I saw the port 10022 was open and I did a telnet connect to the port.
3. As soon as I did the telnet connect it returned me the openssh version and the debian version (check the .png file)
4.I wasn't able to run any sort of commands as whatever I typed returned a protocol mismatch error.
This doesn't necessarily mean a security issue as long as everything is being patched regularly.
Report Details
Additional information and metadata
State
Closed
Substate
Informative
Submitted
Weakness
Information Disclosure