Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Tristan

Pesquisador deThales Digital Factory Red Team
#31544de 53,635
8.1CVSS total
Vulnerabilidades · 1
PT-2023-19250
8.1
2023-02-06
Synopsys · Coverity Connect · CVE-2023-23849
**Name of the Vulnerable Software and Affected Versions** Coverity Connect versions prior to 2022.12.0 **Description** The issue is an unauthenticated Cross-Site Scripting vulnerability. Any web service hosted on the same subdomain can set a cookie for the whole subdomain, which can be used to bypass other mitigations in place for malicious purposes. **Recommendations** For versions prior to 2022.12.0, update to version 2022.12.0 or later to resolve the issue. As a temporary workaround, consider restricting access to web services hosted on the same subdomain to minimize the risk of exploitation.