PT-2023-18209 · Runestone · Runestone

Hsia.Angsh

·

Published

2023-02-09

·

Updated

2023-02-21

·

CVE-2023-21442

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Runestone versions prior to 2.9.09.003 Runestone versions prior to 3.2.01.007
Description The issue is related to improper access control in the Runestone application, allowing local attackers to obtain device location information.
Recommendations For versions prior to 2.9.09.003, update to version 2.9.09.003 or later to resolve the issue. For versions prior to 3.2.01.007, update to version 3.2.01.007 or later to resolve the issue.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2023-21442

Affected Products

Runestone