PT-2023-7247 · Ipswitch · Moveit Transfer
CVE-2023-6218
·
Publicado
2023-11-20
·
Atualizado
2023-12-09
CVSS v2.0
8.3
Alta
| Vetor | AV:N/AC:L/Au:M/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
MOVEit Transfer versions prior to 2022.0.9 (14.0.9)
MOVEit Transfer versions prior to 2022.1.10 (14.1.10)
MOVEit Transfer versions prior to 2023.0.7 (15.0.7)
Description
A privilege escalation path associated with group administrators has been identified, allowing a group administrator to elevate a group member's permissions to the role of an organization administrator. The issue is related to insufficient access control in the software.
Recommendations
For versions prior to 2022.0.9 (14.0.9), update to a version newer than 2022.0.9 to resolve the issue.
For versions prior to 2022.1.10 (14.1.10), update to a version newer than 2022.1.10 to resolve the issue.
For versions prior to 2023.0.7 (15.0.7), update to a version newer than 2023.0.7 to resolve the issue.
As a temporary workaround, consider restricting the privileges of group administrators to minimize the risk of exploitation.
Correção
Improper Privilege Management
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Moveit Transfer