PT-2023-26772 · Strangebee · Thehive

Przemysław Mazurek

·

Published

2023-09-11

·

Updated

2023-09-15

·

CVE-2023-39069

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions StrangeBee TheHive versions 4.1.21 through 5.0.8 Cortex version 3.1.6
Description An issue in the software allows a remote attacker to gain privileges via the Active Directory authentication mechanism.
Recommendations For StrangeBee TheHive versions 4.1.21 through 5.0.8, consider disabling the Active Directory authentication mechanism until a patch is available. For Cortex version 3.1.6, restrict access to the Active Directory authentication mechanism to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2023-39069

Affected Products

Thehive