CVE-2023-2978

MEDIUM4.3EPSS 0.24%

Go package pydio/cells vulnerable to authorization bypass

發布日:2023/5/30修改日:2024/8/20
也稱為:GHSA-mv7x-27pc-8c96GO-2023-1808

描述

A vulnerability was found in Abstrium Pydio Cells 4.2.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Change Subscription Handler. The manipulation leads to authorization bypass. Upgrading to version 4.2.1 is able to address this issue. It is recommended to upgrade the affected component. VDB-230210 is the identifier assigned to this vulnerability.

受影響套件(3)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

參考連結(7)