PT-2023-21220 · Galaxy · Galaxy

Familiardisaster

·

Publicado

2023-03-20

·

Atualizado

2023-03-23

·

CVE-2023-27578

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Galaxy versions prior to 22.01 Galaxy versions prior to 22.05 Galaxy versions prior to 23.0
Description Galaxy is an open-source platform for data analysis. The issue is caused by an insufficient permission check, allowing an attacker to modify or delete any Galaxy Visualization or Galaxy Page if they know the encoded ID of it. Additionally, they can copy or import any Galaxy Visualization given they know the encoded ID of it. Unsupported versions are likely affected as far back as the functionality of Visualizations/Pages exists.
Recommendations For versions prior to 22.01, apply the available patch and restart all Galaxy server processes for the changes to take effect. For versions prior to 22.05, apply the available patch and restart all Galaxy server processes for the changes to take effect. For versions prior to 23.0, apply the available patch and restart all Galaxy server processes for the changes to take effect.

Exploit

Correção

Incorrect Authorization

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-27578
GHSA-J8Q2-R4G5-F22J

Produtos afetados

Galaxy