Unsafe deserialization of untrusted JSON allows execution of arbitrary code on affected releases of the Illumio PCE. Authentication to the API is required to exploit this vulnerability. The flaw exists within the network_traffic API endpoint. An attacker can leverage this vulnerability to execute code in the context of the PCE’s operating system user.
Metrics
Affected Vendors & Products
References
History
Tue, 24 Sep 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: Illumio
Published: 2023-09-26T21:29:36.575Z
Updated: 2024-09-24T13:43:17.802Z
Reserved: 2023-09-25T18:22:12.952Z
Link: CVE-2023-5183
Vulnrichment
Updated: 2024-08-02T07:52:07.639Z
NVD
Status : Analyzed
Published: 2023-09-27T15:19:42.873
Modified: 2023-10-02T19:22:03.777
Link: CVE-2023-5183
Redhat
No data.