Impact
Komodo versions up to 2.3.2 expose internal resource identifiers through the /execute and /execute/{variant} API endpoints, allowing authenticated users to deduce hidden names. The software also logs audit entries before verifying that the requester has the necessary permissions. Authenticated users can therefore inject false audit records that appear to show privileged operations, confusing forensic investigations and potentially hiding malicious activity.
Affected Systems
The vulnerability afflicts MoghTech Komodo, specifically all releases through version 2.3.2. No other version information is supplied.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate threat level. EPSS data is not provided, and the issue is not currently catalogued in CISA’s KEV. Based on the description, the likely attack vector involves an authenticated user sending crafted requests to the /execute endpoints; no remote unauthenticated exploitation is indicated. Once the user guesses a resource name, they can read its internal identifier and create bogus audit log entries that misrepresent privileged actions.
OpenCVE Enrichment