PT-2023-22116 · Xcc · Xcc

Published

2023-04-28

·

Updated

2023-05-08

·

CVE-2023-29058

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions XCC (affected versions not specified)
Description A valid, authenticated XCC user with read-only permissions can modify custom user roles on other user accounts and the user trespass message through the XCC CLI. There is no exposure if SSH is disabled or if there are no users assigned optional read-only permissions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2023-29058

Affected Products

Xcc