PT-2023-20158 · Datahub · Datahub

Artsploit

+6

·

Publicado

2023-02-10

·

Atualizado

2025-12-03

·

CVE-2023-25560

CVSS v3.1

8.2

Alta

VetorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions DataHub (affected versions not specified)
Description The issue concerns the AuthServiceClient in DataHub, which is responsible for managing accounts and authentication. It crafts JSON strings using format strings with user-controlled data, potentially allowing an attacker to manipulate these strings and send them to the backend. This could lead to an authentication bypass, creation of system accounts, and potentially full system compromise.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-25560
GHSA-6RPF-5CFG-H8F3

Produtos afetados

Datahub