Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-48224

Опубликовано: 15 нояб. 2023
Источник: nvd
CVSS3: 8.2
CVSS3: 9.1
EPSS Низкий

Описание

Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcement of privacy regulations in code. The Fides Privacy Center allows data subject users to submit privacy and consent requests to data controller users of the Fides web application. Privacy requests allow data subjects to submit a request to access all person data held by the data controller, or delete/erase it. Consent request allows data subject users to modify their privacy preferences for how the data controller uses their personal data e.g. data sales and sharing consent opt-in/opt-out. If subject_identity_verification_required in the [execution] section of fides.toml or the env var FIDES__EXECUTION__SUBJECT_IDENTITY_VERIFICATION_REQUIRED is set to True on the fides webserver backend, data subjects are sent a one-time code to their email address or phone number, depending on messaging configuration, and the one-time code mus

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ethyca:fides:*:*:*:*:*:*:*:*
Версия до 2.24.0 (исключая)

EPSS

Процентиль: 61%
0.00415
Низкий

8.2 High

CVSS3

9.1 Critical

CVSS3

Дефекты

CWE-338

Связанные уязвимости

CVSS3: 8.2
github
около 2 лет назад

Ethyca Fides Cryptographically Weak Generation of One-Time Codes for Identity Verification

EPSS

Процентиль: 61%
0.00415
Низкий

8.2 High

CVSS3

9.1 Critical

CVSS3

Дефекты

CWE-338