PT-2023-23093 · Unknown · Gotham Orbital-Simulator
Published
2023-10-25
·
Updated
2023-11-03
·
CVE-2023-30967
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Gotham Orbital-Simulator service versions prior to 0.692.0
Description
The issue allows an unauthenticated user to read arbitrary files on the file system due to a Path traversal problem.
Recommendations
For versions prior to 0.692.0, update to version 0.692.0 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive files on the file system until the update is applied.
Fix
Improper Authentication
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gotham Orbital-Simulator