A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user to upload arbitrary content, potentially altering configuration. This is possible through the certificate validation functionality where the API accepts uploaded content and doesn't parse for invalid data
History

Fri, 11 Oct 2024 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: trellix

Published: 2023-11-29T08:53:57.903Z

Updated: 2024-10-11T17:56:19.677Z

Reserved: 2023-11-10T05:17:16.847Z

Link: CVE-2023-6070

cve-icon Vulnrichment

Updated: 2024-08-02T08:21:17.150Z

cve-icon NVD

Status : Modified

Published: 2023-11-29T09:15:21.877

Modified: 2024-11-21T08:43:05.037

Link: CVE-2023-6070

cve-icon Redhat

No data.