Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-35948

Опубликовано: 06 июл. 2023
Источник: nvd
CVSS3: 5.4
CVSS3: 6.1
EPSS Низкий

Описание

Novu provides an API for sending notifications through multiple channels. Versions prior to 0.16.0 contain an open redirect vulnerability in the "Sign In with GitHub" functionality of Novu's open-source repository. It could have allowed an attacker to force a victim into opening a malicious URL and thus, potentially log into the repository under the victim's account gaining full control of the account. This vulnerability only affected the Novu Cloud and Open-Source deployments if the user manually enabled the GitHub OAuth on their self-hosted instance of Novu. Users should upgrade to version 0.16.0 to receive a patch.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:novu:novu:*:*:*:*:*:*:*:*
Версия до 0.16 (исключая)

EPSS

Процентиль: 40%
0.00181
Низкий

5.4 Medium

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-601

EPSS

Процентиль: 40%
0.00181
Низкий

5.4 Medium

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-601