Description
Unsafe deserialization of untrusted JSON allows execution of arbitrary code on affected releases of the Illumio PCE. Authentication to the API is required to exploit this vulnerability. The flaw exists within the network_traffic API endpoint. An attacker can leverage this vulnerability to execute code in the context of the PCE’s operating system user.
No analysis available yet.
Remediation
Vendor Solution
Upgrade to the latest release for a given major version.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-57520 | Unsafe deserialization of untrusted JSON allows execution of arbitrary code on affected releases of the Illumio PCE. Authentication to the API is required to exploit this vulnerability. The flaw exists within the network_traffic API endpoint. An attacker can leverage this vulnerability to execute code in the context of the PCE’s operating system user. |
References
History
Tue, 24 Sep 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Illumio
Published:
Updated: 2024-09-24T13:43:17.802Z
Reserved: 2023-09-25T18:22:12.952Z
Link: CVE-2023-5183
Updated: 2024-08-02T07:52:07.639Z
Status : Modified
Published: 2023-09-27T15:19:42.873
Modified: 2024-11-21T08:41:15.240
Link: CVE-2023-5183
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD