PT-2023-18388 · Modoboa · Modoboa
Published
2023-04-21
·
Updated
2023-05-11
·
CVE-2023-2227
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
modoboa/modoboa versions prior to 2.1.0
Description
The issue is related to improper authorization in the modoboa/modoboa GitHub repository. Specifically, sending a GET request to the endpoint "/api/v2/parameters/core/" returns sensitive information without requiring any authentication or authorization.
Recommendations
For versions prior to 2.1.0, update to version 2.1.0 or later to resolve the issue.
As a temporary workaround, consider restricting access to the "/api/v2/parameters/core/" endpoint until a patch is available.
Exploit
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Modoboa