PT-2023-23176 · Mage Ai · Mage Ai
Kentaro Ishii
·
Published
2023-05-05
·
Updated
2023-05-16
·
CVE-2023-31143
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
mage-ai versions 0.8.34 through 0.8.71
Description
The issue affects mage-ai, an open-source data pipeline tool, when used with user authentication enabled. It allows the terminal to be accessed by users who are not signed in or do not have editor permissions.
Recommendations
For versions 0.8.34 through 0.8.71, update to version 0.8.72 to resolve the issue. As a temporary workaround, consider disabling user authentication until the update can be applied. Restrict access to the terminal to minimize the risk of exploitation.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mage Ai