|Impact||CVSS V3 rating: 7.5 (HIGH)|
|Reported||12th April 2020|
|Reported by||@kuncho, an independent Security Researcher|
|Fixed||20th April 2020|
→ Builds 12.3.xxx - 12.4.195
|Fixed in||Build 12.4.196/12.5.120|
|Overview||Unauthenticated access to API key disclosure from a servlet call|
→ For builds 12.3.xxx - 12.4.195, please upgrade to NCM version 12.4.196.
Unauthenticated access to API key disclosure from a servlet call.
Source and Acknowledgements
Find out more about CVE-2020-11946 from the CVE dictionary.