PT-2023-23176 · Mage Ai · Mage Ai

Kentaro Ishii

·

Published

2023-05-05

·

Updated

2023-05-16

·

CVE-2023-31143

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions mage-ai versions 0.8.34 through 0.8.71
Description The issue affects mage-ai, an open-source data pipeline tool, when used with user authentication enabled. It allows the terminal to be accessed by users who are not signed in or do not have editor permissions.
Recommendations For versions 0.8.34 through 0.8.71, update to version 0.8.72 to resolve the issue. As a temporary workaround, consider disabling user authentication until the update can be applied. Restrict access to the terminal to minimize the risk of exploitation.

Exploit

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2023-31143
GHSA-C6MM-2G84-V4M7
PYSEC-2023-64

Affected Products

Mage Ai