PT-2023-2485 · Unknown · Papercut Ng
Chudypb
+1
·
Published
2023-03-14
·
Updated
2025-05-15
·
CVE-2023-27351
Chudypb
+1
·
Published
2023-03-14
·
Updated
2025-05-15
·
CVE-2023-27351
8.5
High
Base vector | Vector | AV:N/AC:L/Au:N/C:C/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
PaperCut NG version 22.0.5 (Build 63914)
Description:
This issue allows remote attackers to bypass authentication on affected installations. The flaw exists within the `SecurityRequestFilter` class due to improper implementation of the authentication algorithm. An attacker can leverage this to bypass authentication on the system.
Recommendations:
For PaperCut NG version 22.0.5 (Build 63914), consider disabling the `SecurityRequestFilter` class as a temporary workaround until a patch is available. Restrict access to sensitive areas of the system to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Improper Access Control