PT-2023-28997 · Nexkey · Nexkey

Nexryai

·

Publicado

2023-10-04

·

Atualizado

2023-10-11

·

CVE-2023-43805

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nexkey versions prior to 12.121.9
Description The issue is related to incomplete URL validation, which can allow users to bypass authentication and access the job queue dashboard. This is a problem in a decentralized social media platform.
Recommendations For versions prior to 12.121.9, update to version 12.121.9 to resolve the issue. As a temporary workaround, consider blocking access to the vulnerable endpoint using tools such as Cloudflare's WAF.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-43805
GHSA-9FJ2-GJCF-CQQC
GHSA-G8W5-568F-FFWF

Produtos afetados

Nexkey