Impact
Some API routes will print a stack trace when called with missing or invalid parameters revealing sensitive information about the locations of paths that the server is using.
Patches
Users should upgrade to version 3.3.5 which fixes this issue.
Workarounds
Upgrading to a fixed version is necessary to remediate.
References
Xibo Signage Security Advisory
Claroty Team82 Disclosure
Credit
Thanks to Noam Moshe of Claroty Research who discovered this issue.
Impact
Some API routes will print a stack trace when called with missing or invalid parameters revealing sensitive information about the locations of paths that the server is using.
Patches
Users should upgrade to version 3.3.5 which fixes this issue.
Workarounds
Upgrading to a fixed version is necessary to remediate.
References
Xibo Signage Security Advisory
Claroty Team82 Disclosure
Credit
Thanks to Noam Moshe of Claroty Research who discovered this issue.