The vulnerability allows a remote authenticated attacker to read or update arbitrary content of the authentication database via a crafted HTTP request.
By abusing this vulnerability it is possible to exfiltrate other users’ password hashes or update them with arbitrary values and access their accounts.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: bosch
Published: 2024-01-10T13:02:19.652Z
Updated: 2024-08-02T21:23:39.464Z
Reserved: 2023-11-13T13:44:23.705Z
Link: CVE-2023-48253
Vulnrichment
No data.
NVD
Status : Modified
Published: 2024-01-10T13:15:45.803
Modified: 2024-11-21T08:31:19.600
Link: CVE-2023-48253
Redhat
No data.