VYPR
High severity7.5OSV Advisory· Published Aug 16, 2021· Updated Jun 17, 2026

CVE-2021-38712

CVE-2021-38712

Description

OneNav 0.9.12 allows Information Disclosure of the onenav.db3 contents. NOTE: the vendor's recommended solution is to block the access via an NGINX configuration file.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • OneNav/OneNavllm-create2 versions
    <=0.9.12+ 1 more
    • (no CPE)range: <=0.9.12
    • cpe:2.3:a:onenav:onenav:0.9.12:*:*:*:*:*:*:*
  • Range: 0.9.1, 0.9.10, 0.9.11, …

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.