Cacheservice did not correctly check if relative cache object were pointing to the defined absolute location when accessing resources. An attacker with access to the database and a local or restricted network would be able to read arbitrary local file system resources that are accessible by the services system user account. We have improved path validation and make sure that any access is contained to the defined root directory. No publicly available exploits are known.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: OX
Published: 2023-08-02T12:23:09.844Z
Updated: 2024-08-02T11:46:24.602Z
Reserved: 2023-02-22T20:42:56.090Z
Link: CVE-2023-26441
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-08-02T13:15:10.563
Modified: 2024-11-21T07:51:27.563
Link: CVE-2023-26441
Redhat
No data.