Description
An authenticated administrator can upload a SAML configuration file with the wrong format, with the application not checking the correct file format. Every subsequent application request will return an error.

The whole application in rendered unusable until a console intervention.
Published: 2023-08-09
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Upgrade to v22.6.2 or later.


Vendor Workaround

Use internal firewall features to limit access to the web management interface.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-27986 An authenticated administrator can upload a SAML configuration file with the wrong format, with the application not checking the correct file format. Every subsequent application request will return an error. The whole application in rendered unusable until a console intervention.
History

Fri, 20 Sep 2024 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 20 Sep 2024 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Fri, 20 Sep 2024 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1286

Subscriptions

Nozominetworks Cmc Guardian
cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published:

Updated: 2024-09-20T12:09:31.800Z

Reserved: 2023-01-24T10:39:24.300Z

Link: CVE-2023-23903

cve-icon Vulnrichment

Updated: 2024-08-02T10:42:26.840Z

cve-icon NVD

Status : Modified

Published: 2023-08-09T10:15:09.687

Modified: 2024-11-21T07:47:04.113

Link: CVE-2023-23903

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.