Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade github.com/huandu/facebook/v2
to version 2.7.2 or higher.
Affected versions of this package are vulnerable to Information Exposure Through an Error Message in the error message handling process. An attacker can expose sensitive information by causing an HTTP request to fail.
Note
Client applications with the following conditions can be affected: Logs error message from this module, or returns error message to client as something like HTTP response, or uses error messages somewhere.