PT-2023-27378 · Opennms · Opennms Horizon +1
Erik Wynter
·
Published
2023-08-17
·
Updated
2024-10-28
·
CVE-2023-40315
5.3
Medium
Base vector | Vector | AV:A/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions:
OpenMNS Horizon versions 31.0.8 through 32.0.2
Meridian versions prior to 2023.1.5
Description:
The issue allows any user with the `ROLE FILESYSTEM EDITOR` to easily escalate their privileges to `ROLE ADMIN` or any other role. The affected software is intended for installation within an organization's private networks and should not be directly accessible from the Internet. OpenNMS thanks Erik Wynter for reporting this issue.
Recommendations:
To resolve the issue, upgrade to Meridian 2023.1.5 or Horizon 32.0.2 or newer.
As a temporary workaround, consider restricting the use of the `ROLE FILESYSTEM EDITOR` role until a patch is available.
Restrict access to the affected software to minimize the risk of exploitation, following the installation instructions that state the software should not be directly accessible from the Internet.
Exploit
Fix
Incorrect Authorization
Weakness Enumeration
Related Identifiers
Affected Products
References · 13
- 🔥 https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/opennms_horizon_authenticated_rce.rb⭐ 34266 🔗 14003 · Exploit
- https://github.com/OpenNMS/opennms/pull/6250⭐ 982 🔗 585 · Patch
- https://nvd.nist.gov/vuln/detail/CVE-2023-40315 · Security Note
- https://osv.dev/vulnerability/CVE-2023-40315 · Vendor Advisory
- https://osv.dev/vulnerability/GHSA-hf5p-f83x-5q2g · Vendor Advisory
- https://github.com/OpenNMS/opennms⭐ 1049 🔗 596 · Note
- https://github.com/OpenNMS/opennms/commit/f2caf7d0b9db58b59e98506490aaca37fbf243b6⭐ 982 🔗 585 · Note
- https://t.me/cvenotify/99801 · Telegram Post
- https://twitter.com/TechFishNews/status/1692303994742591559 · Twitter Post
- https://twitter.com/CVEnew/status/1692253038407250113 · Twitter Post
- https://t.me/cibsecurity/68808 · Telegram Post
- https://docs.opennms.com/meridian/2023/releasenotes/changelog.html#releasenotes-changelog-Meridian-2023.1.5 · Note
- https://twitter.com/VulmonFeeds/status/1692312784027967529 · Twitter Post