Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Tristan

Researcher fromThales Digital Factory Red Team
#31486of 53,634
8.1Total CVSS
Vulnerabilities · 1
PT-2023-19250
8.1
2023-02-06
Synopsys · Coverity Connect · CVE-2023-23849
**Name of the Vulnerable Software and Affected Versions** Coverity Connect versions prior to 2022.12.0 **Description** The issue is an unauthenticated Cross-Site Scripting vulnerability. Any web service hosted on the same subdomain can set a cookie for the whole subdomain, which can be used to bypass other mitigations in place for malicious purposes. **Recommendations** For versions prior to 2022.12.0, update to version 2022.12.0 or later to resolve the issue. As a temporary workaround, consider restricting access to web services hosted on the same subdomain to minimize the risk of exploitation.