Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-6070

Опубликовано: 29 нояб. 2023
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user to upload arbitrary content, potentially altering configuration. This is possible through the certificate validation functionality where the API accepts uploaded content and doesn't parse for invalid data

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:trellix:enterprise_security_manager:*:*:*:*:*:*:*:*
Версия до 11.6.8 (исключая)

EPSS

Процентиль: 29%
0.00103
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 4.3
github
около 2 лет назад

A server-side request forgery vulnerability in ESM prior to version 11.6.8 allows a low privileged authenticated user to upload arbitrary content, potentially altering configuration. This is possible through the certificate validation functionality where the API accepts uploaded content and doesn't parse for invalid data

EPSS

Процентиль: 29%
0.00103
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-918