GBrowse accepts files with any formats uploaded and places them in the area accessible through unauthenticated web requests. Therefore, anyone who can upload files through the product may execute arbitrary code on the server.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2023-07-25T05:01:48.955Z

Updated: 2024-08-02T15:25:36.265Z

Reserved: 2023-05-11T04:09:45.896Z

Link: CVE-2023-32637

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-07-25T06:15:10.893

Modified: 2024-08-02T16:15:21.493

Link: CVE-2023-32637

cve-icon Redhat

No data.